windows-shell-bypass
SkillSecurityGenerates malicious Windows shortcut files designed to bypass SmartScreen and Mark-of-the-Web warnings.
Available today. Use it from your connected AI after setup.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the windows-shell-bypass skill
About this skill
🛡⚔️AI-Powered Penetration Testing Framework with automated vulnerability scanning, multi-agent system, and compliance reporting🛡⚔️
What this skill tells your AI
The instructions your AI receives, as published by shadd0wtaka/zen-ai-pentest in skills/module-windows-shell-bypass/SKILL.md and read by ahel’s review.
CVE-2026-21510: Windows Shell Security Feature Bypass
Category: exploitation — Exploitation Module
Overview
CVE-2026-21510: Windows Shell Security Feature Bypass CVSS: 8.8 (High) Type: Security Feature Bypass (SmartScreen/MOTW)
This module creates malicious LNK files that bypass Windows SmartScreen and Mark of the Web (MOTW) protections.
Technical Details:
- Exploits improper handling of URL zones in Windows Shell
- Bypasses "Mark of the Web" (MOTW) security warnings
- Allows silent execution of malicious payloads
Affected Systems:
- Windows 10 (21H2+)
- Windows 11 (bis 25H2)
- Windows Server 2012-
Usage
Agent Integration
- Agent persona: auto-selected from category 'exploitation'
- MCP:
- API: with {"tool_name": "windows_shell_bypass", "target": "example.com"}
Signals
- GitHub stars
- 469
- Forks
- 81
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
module-windows-shell-bypass- Source
- github.com/shadd0wtaka/zen-ai-pentest