active-directory-kerberos-attacks

Warn

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous command-line examples for high-risk offensive security tools including Impacket, Rubeus, and Mimikatz for attacking Active Directory.- [DATA_EXFILTRATION]: Instructions provide specific methods for extracting sensitive authentication data, such as krbtgt hashes, service account tickets, and user TGTs, from a target environment.- [PROMPT_INJECTION]: The skill has a potential surface for indirect prompt injection by ingesting and acting upon untrusted data from Active Directory environments (e.g., user objects, SPNs, and group memberships).
  • Ingestion points: Target Active Directory environment data (user lists, SPNs, computer objects, and ACLs) as described in SKILL.md and KERBEROS_ATTACK_CHAINS.md.
  • Boundary markers: The skill does not provide explicit instructions to the agent to disregard instructions potentially embedded in the data retrieved from the target environment.
  • Capability inventory: The skill enables high-impact capabilities including file system access, network communication with Domain Controllers, and execution of offensive tools (Impacket, Rubeus, Mimikatz).
  • Sanitization: No sanitization or validation logic is specified for the data ingested from the target environment before it is passed to sensitive tool commands.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 21, 2026, 01:23 PM
Security Audit — agent-trust-hub — active-directory-kerberos-attacks