bloodhound
Audited by Socket on Sep 15, 2026
2 alerts found:
Securityx2SUSPICIOUS: the skill is internally coherent as an AD attack-path mapping guide, but its real footprint is an offensive security workflow for an AI agent, including stealth collection, credentialed enumeration, and follow-on abuse guidance. No confirmed malware or hidden exfiltration is shown, yet the outdated shortlink installer and credential use with third-party collectors make it high-risk and inappropriate for general-purpose agent deployment.
This fragment is an explicit BloodHound-based Active Directory reconnaissance and privilege-escalation workflow. It presents a significant misuse and operational security risk in unauthorized environments, particularly because it identifies Domain Admin, ADCS, ACL, session, DCSync, and persistence paths. However, the visible code contains no clear malicious package behavior such as credential theft, covert exfiltration, persistence installation, destructive actions, or obfuscated payloads. The plaintext password argument is a credential-handling concern if populated with a real secret.