windows-ad

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: Provides example commands for various security tools such as NetExec (nxc), BloodHound (bloodhound-python), Certipy, and Impacket. These are intended for authorized security research and are preceded by a mandatory confirmation gate requiring user authorization and target confirmation.
  • [EXTERNAL_DOWNLOADS]: References an external community repository on GitHub (zhaoxuya520/reverse-skill) as its source. This reference is informational and does not initiate automated downloads or remote code execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents techniques that involve processing external data (e.g., AD CS templates, NTLM relaying). However, it does not ingest untrusted data directly into the agent context in an exploitable way, and its primary function is instructional.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 09:23 PM
Security Audit — agent-trust-hub — windows-ad