gpo-abuse
Warn
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the GPOHound tool directly from a third-party GitHub repository (github.com/cogiceo/GPOHound) using pipx. Executing code directly from unverified sources is a security risk.
- [REMOTE_CODE_EXECUTION]: The instructions include multiple examples of using PowerShell's IEX (Invoke-Expression) to download and execute scripts directly from a remote URL (http://ATTACKER/shell.ps1).
- [COMMAND_EXECUTION]: The skill facilitates the execution of various exploitation tools such as SharpGPOAbuse, pyGPOAbuse, and netexec that are designed to perform highly privileged modifications to a domain's security policy.
Audit Metadata