bloodyad

Warn

Audited by Socket on Sep 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its stated purpose matches its capabilities, and the referenced tools appear to be legitimate upstream security tools installed via normal Python/package channels, so this is not confirmed malware. However, the skill is an offensive AD exploitation playbook for an AI agent, handling powerful credentials and enabling real privilege-escalation and persistence actions; that makes it a high-security-risk exploit skill even without deceptive installers or clear exfiltration behavior.

Confidence: 90%Severity: 83%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:46 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fbloodyad%2F@ad427233e98ac21869fd62cd2ce48ec5401db393bbc200f2ee81af2b56f65f96
Security Audit — socket — bloodyad