credential-dumping

Fail

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates the execution of numerous high-risk administrative and penetration testing tools, including secretsdump.py, mimikatz, netexec, bloodyAD, gMSADumper.py, sqlcmd, ntdsutil.exe, vssadmin, and diskshadow.exe to perform sensitive operations.
  • [DATA_EXFILTRATION]: Provides detailed procedures for extracting and saving critical security data, including the NTDS.dit database, SAM/SYSTEM/SECURITY registry hives, and encrypted configurations from Azure AD Connect. It specifically instructs the agent to save this sensitive evidence to local directories.
  • [REMOTE_CODE_EXECUTION]: Directs the agent to execute various Python scripts (gMSADumper.py, GoldenGMSA.py, Get-LAPSPassword.py, Get-GPPPassword.py) and includes instructions for generating and executing a PowerShell script (decrypt_adsync.ps1) that dynamically loads system DLLs (mcrypt.dll) for credential decryption.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface through the use of external state data.
  • Ingestion points: External context is ingested via the get_state_summary() call to a state management server.
  • Boundary markers: No specific delimiters or warnings to ignore embedded instructions are present for the ingested state data.
  • Capability inventory: The skill has broad capabilities including subprocess execution of pentesting tools, file system writes (evidence logging, script generation), and network-based directory queries (LDAP/SMB).
  • Sanitization: No sanitization or validation of the external state input is described.
  • [DATA_EXPOSURE]: Documents techniques for reading LAPS (Local Administrator Password Solution) and gMSA (Group Managed Service Account) credentials directly from Active Directory object attributes.
  • [PRIVILEGE_ESCALATION]: Outlines methods for escalating privileges within a domain, such as exploiting CVE-2025-21293 (dMSA successor manipulation) and performing DCSync replication attacks to compromise the entire domain database.
  • [PERSISTENCE]: Explains how to establish persistence by extracting the KDS root key (GoldenGMSA technique) to compute service account passwords offline or by modifying the DsrmAdminLogonBehavior to enable network logon via the DSRM Administrator account.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 6, 2026, 09:15 AM
Security Audit — agent-trust-hub — credential-dumping