initial-access-phishing
Warn
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: MEDIUMPROMPT_INJECTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill provides instructions for bypassing security controls like MFA and email gateways. It also identifies ingestion points for untrusted OSINT data (e.g., LinkedIn, GitHub) for social engineering pretexts without defined sanitization or boundary markers.
- [DATA_EXFILTRATION]: Outlines methods for stealing session cookies and OAuth access/refresh tokens through reverse proxies and deceptive consent flows.
- [EXTERNAL_DOWNLOADS]: Mentions the use of external offensive tools including
evilginx3,Modlishka,TokenTactics,AADInternals, andgophish. - [NO_CODE]: The file contains only instructional text and does not include any executable scripts.
Audit Metadata