kerberos-advanced-attack
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill contains technical instructions and command-line examples for executing well-known security tools such as Impacket's scripts (e.g., getTGT.py, secretsdump.py, addcomputer.py), Rubeus, NetExec, bloodyAD, and noPac.py. These tools are used for Active Directory security auditing and exploitation within the context of a penetration test.\n- [PROMPT_INJECTION]: The skill involves processing data from untrusted sources, which presents an indirect prompt injection surface (Category 8).\n
- Ingestion points: The skill utilizes tools that ingest data from LDAP directory attributes, network traffic captures (via PCredz), and Kerberos protocol responses.\n
- Boundary markers: There are no specific delimiters or instructions provided to separate tool output from agent instructions or to ignore potentially malicious embedded content.\n
- Capability inventory: The skill enables command execution via shell and various network-based protocol interactions (LDAP, Kerberos, SMB) through the included tool commands.\n
- Sanitization: No explicit validation, filtering, or sanitization of the data retrieved from target systems is described before it is processed by the agent.
Audit Metadata