powerview

Fail

Audited by Socket on Sep 5, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as an Active Directory recon/offensive security guide, but that purpose itself gives an AI agent high-risk security-audit and post-compromise capabilities. No clear credential theft or covert exfiltration is shown, yet the reconnaissance, lateral-movement mapping, and exploitation preparation make it inappropriate as a general benign admin skill.

Confidence: 91%Severity: 86%
MalwareHIGH
references/acl-abuse-patterns.md

This fragment is highly consistent with malicious intent: it provides concrete, step-by-step instructions to compromise Active Directory via ACL abuse (GenericAll/WriteDACL/WriteOwner and related rights), Kerberos delegation/RBCD configuration, and credential/ticket attacks (Kerberoasting, coercion-based TGT capture, Mimikatz/ticket handling, offline cracking, and shadow-credential concepts). There is no benign protective logic; the content is operationally actionable for privilege escalation and domain compromise. Treat as a critical security risk if encountered in a software supply chain context.

Confidence: 78%Severity: 98%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:45 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fpowerview%2F@60fa5777cdf3ce408650af723d76aaddd2c3b47dd73fe8d22313664e12b833b3
Security Audit — socket — powerview