offensive-network-attacks
Warn
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for executing numerous shell commands using
sudoto manipulate network traffic. Tools included arebettercap,responder,ettercap,yersinia, andmitm6. - [PRIVILEGE_ESCALATION]: Instructions frequently use
sudoto gain the permissions necessary for raw socket access and network interface control. It also describes techniques like NTLM relaying to ADCS for certificate-based privilege escalation within a domain. - [INDIRECT_PROMPT_INJECTION]: The skill's methodology involves capturing and analyzing unauthenticated network traffic, which serves as an untrusted input source.
- Ingestion points: Raw network packets and broadcast/multicast queries (LLMNR, mDNS, ARP, DHCP) processed by monitoring tools like
Responderandtcpdumpas described in SKILL.md. - Boundary markers: None; the agent is not provided with delimiters to separate its instructions from the data it intercepts.
- Capability inventory: The skill has access to shell execution via
sudo, Python script execution (scapy), and file system writes for capturing packet logs. - Sanitization: No sanitization or validation of intercepted network protocols is specified before the data is processed or relayed.
Audit Metadata