kerberos-ticket-forging

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous command-line examples for executing powerful offensive security tools, including the Impacket suite (ticketer.py, secretsdump.py, psexec.py, lookupsid.py, ticketConverter.py), Rubeus, mimikatz, and bloodyAD. These tools are used to perform privilege escalation and maintain domain persistence through Kerberos ticket manipulation.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes untrusted data from external sources during execution.
  • Ingestion points: The skill reads data from the ./engagement/ directory and incorporates output from the get_state_summary() MCP tool into its operational context.
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are present when processing this external data.
  • Capability inventory: The skill possesses high-impact capabilities, including remote code execution via psexec.py, wmiexec.py, and dcomexec.py, as well as sensitive data extraction via secretsdump.py.
  • Sanitization: The instructions do not include steps for sanitizing, validating, or escaping the external content before it influences the agent's decision-making process.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 09:15 AM
Security Audit — agent-trust-hub — kerberos-ticket-forging