skills/ktol1/redteam-agent/redteam/Gen Agent Trust Hub

redteam

Fail

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: HIGHCOMMAND_EXECUTIONCREDENTIALS_UNSAFEREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides detailed instructions and command-line arguments for running numerous offensive security tools, including fscan.exe, gogo.exe, NetExec (nxc), and nuclei.exe, to perform network reconnaissance and vulnerability identification.
  • [CREDENTIALS_UNSAFE]: It contains explicit guidance for harvesting high-privilege credentials, such as using impacket-secretsdump for DCSync attacks to extract domain hashes and mimikatz for local credential extraction from SAM and LSA.
  • [REMOTE_CODE_EXECUTION]: The skill facilitates lateral movement and remote execution through instructions for impacket-wmiexec, impacket-psexec, and impacket-dcomexec. It also features an upload_and_exec function designed to deploy and execute arbitrary payloads on remote systems.
  • [DATA_EXFILTRATION]: It instructs on setting up network pivots and tunnels using chisel and performing NTLM relay attacks via ntlmrelayx, which can be leveraged to bypass network boundaries and exfiltrate data.
  • [EXTERNAL_DOWNLOADS]: The documentation references an automated installation script (install_tools.py) and specifies several external Python dependencies (e.g., bloodhound, pywerview, bloodyAD) to be retrieved from public package registries.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 18, 2026, 04:38 PM
Security Audit — agent-trust-hub — redteam