powerview
Audited by Socket on Sep 5, 2026
2 alerts found:
SecurityMalwareSUSPICIOUS: the skill is internally consistent as an Active Directory recon/offensive security guide, but that purpose itself gives an AI agent high-risk security-audit and post-compromise capabilities. No clear credential theft or covert exfiltration is shown, yet the reconnaissance, lateral-movement mapping, and exploitation preparation make it inappropriate as a general benign admin skill.
This fragment is highly consistent with malicious intent: it provides concrete, step-by-step instructions to compromise Active Directory via ACL abuse (GenericAll/WriteDACL/WriteOwner and related rights), Kerberos delegation/RBCD configuration, and credential/ticket attacks (Kerberoasting, coercion-based TGT capture, Mimikatz/ticket handling, offline cracking, and shadow-credential concepts). There is no benign protective logic; the content is operationally actionable for privilege escalation and domain compromise. Treat as a critical security risk if encountered in a software supply chain context.