windows-uac-bypass

Fail

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous commands to manipulate the Windows Registry to hijack the execution flow of trusted binaries (e.g., fodhelper.exe, eventvwr.exe, sdclt.exe), resulting in arbitrary command execution at high integrity levels.
  • [COMMAND_EXECUTION]: Instructions for establishing persistence through multiple vectors, including Registry 'Run' keys, Startup folders, Winlogon modifications, and Active Setup hijacking, allowing for unauthorized long-term execution.
  • [PROMPT_INJECTION]: The skill instructs the agent to perform actions that circumvent system security policies (UAC) and provides a logic framework for selecting the most effective exploit based on target configuration.
  • [REMOTE_CODE_EXECUTION]: The skill details the generation and installation of malicious MSI packages to exploit the 'AlwaysInstallElevated' policy, enabling the execution of attacker-controlled code with SYSTEM privileges.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 6, 2026, 09:16 AM
Security Audit — agent-trust-hub — windows-uac-bypass