smb-pentesting
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides a comprehensive collection of shell commands for various security testing tools such as
nmap,enum4linux,crackmapexec, andsmbclientto be used against remote targets. - [PROMPT_INJECTION]: The skill includes instructions to interact with, list, and download files from untrusted external SMB shares, which presents a surface for indirect prompt injection. Ingestion points: Phase 2.2 and Phase 6.3 involve recursive listing and downloading via
smbclientandsmbmap. Boundary markers: No explicit boundary markers or warnings are defined for retrieved content. Capability inventory: The environment includes powerful execution tools likepsexec.pyandwmiexec.py. Sanitization: No sanitization or validation of content retrieved from shares is specified. - [REMOTE_CODE_EXECUTION]: The file
references/smb-exploitation.mdincludes a reverse shell command example (nc -e /bin/sh) associated with documentation forCVE-2007-2447. This is provided as an example for offensive testing and is not executed by the skill against the local environment.
Audit Metadata