bloodhound

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as an AD attack-path mapping guide, but its real footprint is an offensive security workflow for an AI agent, including stealth collection, credentialed enumeration, and follow-on abuse guidance. No confirmed malware or hidden exfiltration is shown, yet the outdated shortlink installer and credential use with third-party collectors make it high-risk and inappropriate for general-purpose agent deployment.

Confidence: 91%Severity: 79%
SecurityMEDIUM
references/cypher-queries-and-api.md

This fragment is an explicit BloodHound-based Active Directory reconnaissance and privilege-escalation workflow. It presents a significant misuse and operational security risk in unauthorized environments, particularly because it identifies Domain Admin, ADCS, ACL, session, DCSync, and persistence paths. However, the visible code contains no clear malicious package behavior such as credential theft, covert exfiltration, persistence installation, destructive actions, or obfuscated payloads. The plaintext password argument is a credential-handling concern if populated with a real secret.

Confidence: 98%Severity: 72%
Audit Metadata
Analyzed At
Sep 15, 2026, 09:59 AM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fbloodhound%2F@c84ffcea373b9b3cf78743f8a5f6ac1d823b5c93d9427e1e86f5f900a54b259a
Security Audit — socket — bloodhound