offensive-network-attacks

Warn

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for executing numerous shell commands using sudo to manipulate network traffic. Tools included are bettercap, responder, ettercap, yersinia, and mitm6.
  • [PRIVILEGE_ESCALATION]: Instructions frequently use sudo to gain the permissions necessary for raw socket access and network interface control. It also describes techniques like NTLM relaying to ADCS for certificate-based privilege escalation within a domain.
  • [INDIRECT_PROMPT_INJECTION]: The skill's methodology involves capturing and analyzing unauthenticated network traffic, which serves as an untrusted input source.
  • Ingestion points: Raw network packets and broadcast/multicast queries (LLMNR, mDNS, ARP, DHCP) processed by monitoring tools like Responder and tcpdump as described in SKILL.md.
  • Boundary markers: None; the agent is not provided with delimiters to separate its instructions from the data it intercepts.
  • Capability inventory: The skill has access to shell execution via sudo, Python script execution (scapy), and file system writes for capturing packet logs.
  • Sanitization: No sanitization or validation of intercepted network protocols is specified before the data is processed or relayed.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 27, 2026, 02:26 PM
Security Audit — agent-trust-hub — offensive-network-attacks