kerberos-pentesting
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or unauthorized data exfiltration techniques were identified. The skill's focus on Active Directory and Kerberos security testing is legitimate and well-documented.\n- [COMMAND_EXECUTION]: The skill includes numerous shell commands for using security tools such as Nmap, Impacket, and Rubeus. These commands are standard for the intended purpose of network service auditing.\n- [EXTERNAL_DOWNLOADS]: Instructions reference the installation of security tools from well-known repositories on GitHub and package registries like PyPI. These resources are trusted within the cybersecurity community for the tasks described.\n- [PROMPT_INJECTION]: The skill describes a methodology that involves processing data from external tool outputs and local files, which presents a potential surface for indirect prompt injection.\n
- Ingestion points: Data from scanning tools (Nmap), enumeration results (Kerbrute), and local wordlists (users.txt).\n
- Boundary markers: None explicitly mentioned to separate untrusted data from agent instructions.\n
- Capability inventory: High; the agent is instructed to use various shell-based tools with network and file system access.\n
- Sanitization: Not specifically detailed in the instructional methodology.
Audit Metadata