skills/mukul975/anthropic-cybersecurity-skills/auditing-entra-id-with-aadinternals/Gen Agent Trust Hub
auditing-entra-id-with-aadinternals
Fail
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: CRITICALCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
scripts/agent.pyto launch PowerShell cmdlets from the AADInternals module. It programmatically identifies the available PowerShell shell (pwsh or powershell) and executes specific commands provided by the user viasubprocess.run. - [EXTERNAL_DOWNLOADS]: The documentation provides instructions to install the 'AADInternals' module directly from the official Microsoft PowerShell Gallery. It also references a Python-based reconnaissance tool from a known security research organization (Synacktiv).
- [SAFE]: The URLs identified by automated scanners (aadinternals.com) are the official documentation and technical blog sites for the toolkit used by this skill. These resources provide the necessary technical context for the tool's cmdlets and the Golden SAML techniques it is designed to audit. The behaviors, while offensive in nature (token forgery, federation backdoors), are explicitly scoped for authorized security testing and defensive validation, matching the skill's stated intent.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- Contains 4 malicious URL(s) - DO NOT USE
Audit Metadata