Windows Privilege Escalation
Fail
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: HIGHPRIVILEGE_ESCALATIONDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSOBFUSCATIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFEREMOTE_CODE_EXECUTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill provides instructions for modifying service binary paths using
sc configto execute arbitrary payloads as SYSTEM. It also details methods for exploiting theAlwaysInstallElevatedregistry policy and using token impersonation tools likeJuicyPotatoandPrintSpooferto gain elevated privileges. - [DATA_EXFILTRATION]: Instructions include techniques for extracting sensitive credential data from the SAM and SYSTEM registry hives, harvesting passwords from various configuration files (e.g.,
unattend.xml), and capturing cleartext passwords from the registry (e.g., Winlogon). It demonstrates the use ofmsfvenomandnetcatto establish reverse shells to an external IP address. - [COMMAND_EXECUTION]: The skill makes extensive use of powerful Windows management tools such as
wmic,sc,netsh, andregto enumerate system state, modify configurations, and execute malicious binaries or scripts. - [EXTERNAL_DOWNLOADS]: The workflow relies on multiple external, third-party exploitation tools and scripts (e.g.,
WinPEAS,Seatbelt,JuicyPotato,mimikatz) that are not hosted by trusted vendors or included in the skill repository. - [OBFUSCATION]: The skill includes a Base64-encoded password example and suggests using PowerShell's
-encparameter to bypass execution policies and potentially evade monitoring. - [CREDENTIALS_UNSAFE]: The documentation contains hardcoded example credentials, including a Base64-encoded password string (
U2VjcmV0U2VjdXJlUGFzc3dvcmQxMjM0Kgo=) and cleartext passwords in registry query examples (e.g.,P@ssw0rd123). - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted system data—such as file names, registry keys, and process outputs—into the agent's context without sanitization or protective boundary markers.
- [REMOTE_CODE_EXECUTION]: The skill instructs the user to download and execute code from remote sources, including using
runaswith credentials to execute binaries from a network share (\\10.10.10.10\share\evil.exe) and establishing reverse shell connections to external IPs.
Recommendations
- AI detected serious security threats
Audit Metadata