active-directory-acl-abuse
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill contains a large volume of instructions for executing powerful security tools (such as Impacket, PowerView, Mimikatz, and SharpHound) to modify Active Directory objects, reset passwords, and dump credentials. While consistent with a penetration testing playbook, these commands represent highly sensitive operations.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and act upon data retrieved from complex Active Directory environments, such as BloodHound paths and object descriptions. This creates a surface for indirect prompt injection where maliciously crafted metadata in the target environment could attempt to influence the agent's logic.
- Ingestion points: BloodHound data collection results, Neo4j/Cypher query outputs, and Active Directory object properties (e.g., computer and user descriptions).
- Boundary markers: The skill does not provide explicit markers or instructions to isolate or ignore potentially malicious content within the processed AD data.
- Capability inventory: The skill utilizes significant capabilities including shell command execution, sensitive credential harvesting (DCSync), and system-level configuration changes (GPO abuse).
- Sanitization: No evidence of sanitization or validation of the data ingested from the external Active Directory environment was found.
Audit Metadata