bloodyad
Warn
Audited by Socket on Sep 5, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/HIGH-RISK skill. Its stated purpose matches its capabilities, and the referenced tools appear to be legitimate upstream security tools installed via normal Python/package channels, so this is not confirmed malware. However, the skill is an offensive AD exploitation playbook for an AI agent, handling powerful credentials and enabling real privilege-escalation and persistence actions; that makes it a high-security-risk exploit skill even without deceptive installers or clear exfiltration behavior.
Confidence: 90%Severity: 83%
Audit Metadata