coercer
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent but its purpose is explicitly offensive—forcing Windows authentication to attacker-controlled infrastructure for hash capture and NTLM relay. There is no clear malware payload or hidden exfiltration beyond the declared attack flow, but it enables credential interception and unauthorized access attempts, making it a high-risk security skill rather than a benign automation aid.
Confidence: 93%Severity: 89%
Audit Metadata