auditing-entra-id-with-aadinternals

Fail

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: CRITICALCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses scripts/agent.py to launch PowerShell cmdlets from the AADInternals module. It programmatically identifies the available PowerShell shell (pwsh or powershell) and executes specific commands provided by the user via subprocess.run.
  • [EXTERNAL_DOWNLOADS]: The documentation provides instructions to install the 'AADInternals' module directly from the official Microsoft PowerShell Gallery. It also references a Python-based reconnaissance tool from a known security research organization (Synacktiv).
  • [SAFE]: The URLs identified by automated scanners (aadinternals.com) are the official documentation and technical blog sites for the toolkit used by this skill. These resources provide the necessary technical context for the tool's cmdlets and the Golden SAML techniques it is designed to audit. The behaviors, while offensive in nature (token forgery, federation backdoors), are explicitly scoped for authorized security testing and defensive validation, matching the skill's stated intent.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • Contains 4 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 6, 2026, 05:39 AM
Security Audit — agent-trust-hub — auditing-entra-id-with-aadinternals