smb-pentesting

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides a comprehensive collection of shell commands for various security testing tools such as nmap, enum4linux, crackmapexec, and smbclient to be used against remote targets.
  • [PROMPT_INJECTION]: The skill includes instructions to interact with, list, and download files from untrusted external SMB shares, which presents a surface for indirect prompt injection. Ingestion points: Phase 2.2 and Phase 6.3 involve recursive listing and downloading via smbclient and smbmap. Boundary markers: No explicit boundary markers or warnings are defined for retrieved content. Capability inventory: The environment includes powerful execution tools like psexec.py and wmiexec.py. Sanitization: No sanitization or validation of content retrieved from shares is specified.
  • [REMOTE_CODE_EXECUTION]: The file references/smb-exploitation.md includes a reverse shell command example (nc -e /bin/sh) associated with documentation for CVE-2007-2447. This is provided as an example for offensive testing and is not executed by the skill against the local environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 03:50 PM
Security Audit — agent-trust-hub — smb-pentesting