active-directory-acl-abuse

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains a large volume of instructions for executing powerful security tools (such as Impacket, PowerView, Mimikatz, and SharpHound) to modify Active Directory objects, reset passwords, and dump credentials. While consistent with a penetration testing playbook, these commands represent highly sensitive operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and act upon data retrieved from complex Active Directory environments, such as BloodHound paths and object descriptions. This creates a surface for indirect prompt injection where maliciously crafted metadata in the target environment could attempt to influence the agent's logic.
  • Ingestion points: BloodHound data collection results, Neo4j/Cypher query outputs, and Active Directory object properties (e.g., computer and user descriptions).
  • Boundary markers: The skill does not provide explicit markers or instructions to isolate or ignore potentially malicious content within the processed AD data.
  • Capability inventory: The skill utilizes significant capabilities including shell command execution, sensitive credential harvesting (DCSync), and system-level configuration changes (GPO abuse).
  • Sanitization: No evidence of sanitization or validation of the data ingested from the external Active Directory environment was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:14 PM
Security Audit — agent-trust-hub — active-directory-acl-abuse