gpo-abuse

Warn

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the GPOHound tool directly from a third-party GitHub repository (github.com/cogiceo/GPOHound) using pipx. Executing code directly from unverified sources is a security risk.
  • [REMOTE_CODE_EXECUTION]: The instructions include multiple examples of using PowerShell's IEX (Invoke-Expression) to download and execute scripts directly from a remote URL (http://ATTACKER/shell.ps1).
  • [COMMAND_EXECUTION]: The skill facilitates the execution of various exploitation tools such as SharpGPOAbuse, pyGPOAbuse, and netexec that are designed to perform highly privileged modifications to a domain's security policy.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 6, 2026, 09:15 AM
Security Audit — agent-trust-hub — gpo-abuse