competition-windows-pivot
Fail
Audited by Snyk on Jun 20, 2026
Risk Level: CRITICAL
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill explicitly instructs recovering and preserving raw credential artifacts (SAM, NTDS, DPAPI, LSA, ticket fields, hashes, cookies, etc.) and to record/replay them, which requires the LLM to handle and potentially output secret values verbatim, creating a high exfiltration risk.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). The skill provides explicit, actionable instructions to locate, extract, and replay Windows credential material (SAM, NTDS, DPAPI, LSA secrets, Kerberos tickets) and to perform host-to-host pivoting and privilege escalation, directly enabling credential theft, lateral movement, and remote compromise.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 1.00). 该技能明确指示访问并提取敏感的操作系统凭证存储与可重放的认证材料(SAM、NTDS、LSA、DPAPI、LSASS、票据等)并重放以实现主机间移动,这些操作需要或会导致提升/滥用特权并改变主机安全状态,因此会危及运行该代理的机器。
Issues (3)
W007
HIGHInsecure credential handling detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata