coercer

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent but its purpose is explicitly offensive—forcing Windows authentication to attacker-controlled infrastructure for hash capture and NTLM relay. There is no clear malware payload or hidden exfiltration beyond the declared attack flow, but it enables credential interception and unauthorized access attempts, making it a high-risk security skill rather than a benign automation aid.

Confidence: 93%Severity: 89%
Audit Metadata
Analyzed At
Sep 15, 2026, 09:58 AM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fcoercer%2F@a9d8d5e3bb0c685135d12532d29157abfc47619104d08b36616ef5971085db70
Security Audit — socket — coercer