network-protocol-attacks

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill includes an "AI LOAD INSTRUCTION" block in SKILL.md that attempts to influence the agent's behavior by prescribing an "Expert" persona and directing it toward specific attack chains that are claimed to be missed by base models.\n- [COMMAND_EXECUTION]: The skill provides a comprehensive list of commands for executing network-level attacks using tools such as bettercap, responder, and ntlmrelayx. These tools are used for ARP spoofing, name resolution poisoning, and NTLM relaying, which are high-risk operations intended to intercept network traffic.\n- [PRIVILEGE_ESCALATION]: Several provided commands require administrative or root privileges to execute, such as modifying kernel-level IP forwarding settings (/proc/sys/net/ipv4/ip_forward) and loading kernel modules for VLAN management (modprobe 8021q).\n- [INDIRECT_PROMPT_INJECTION]: The skill describes processes for ingesting untrusted network protocol data (e.g., LLMNR, NBT-NS, DHCPv6) via Responder and mitm6, which flows into the agent's execution context.\n
  • Ingestion points: Network traffic captured through Responder and mitm6 (documented in NAME_RESOLUTION_POISONING.md).\n
  • Boundary markers: There are no explicit markers or instructions provided to handle or ignore malicious content embedded within the captured network data.\n
  • Capability inventory: The skill demonstrates high capability for arbitrary shell command execution and unauthorized network communication.\n
  • Sanitization: The skill does not mention any sanitization or validation of captured authentication hashes or tool outputs before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:14 PM
Security Audit — agent-trust-hub — network-protocol-attacks