winrm-pentesting

Fail

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: CRITICALREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides documentation for executing remote payloads on target systems, including techniques to download and run PowerShell scripts from attacker-controlled servers using the Invoke-Expression (iex) command structure.\n- [REMOTE_CODE_EXECUTION]: Automated antivirus and reputation scanners identified malicious signatures in SKILL.md and references/winrm-techniques.md. The detection Clip:Powershell-EL [Drp] highlights patterns associated with PowerShell-based droppers used to deliver and execute code.\n- [COMMAND_EXECUTION]: The skill facilitates the use of powerful administrative tools such as Invoke-Command, Enter-PSSession, wmic, and PsExec for remote system management. It also includes instructions for using ntlmrelayx.py with elevated privileges to perform NTLM relay attacks.
Recommendations
  • CRITICAL: 2 infected file(s) detected - DO NOT USE
  • CRITICAL: 2 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 12, 2026, 03:49 PM
Security Audit — agent-trust-hub — winrm-pentesting