responder

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

High-risk offensive security skill. Its capabilities align with its stated purpose, but that purpose is to poison local name resolution, capture authentication hashes, and support relay/cracking workflows, which is dangerous for an AI agent even without overt malware or suspicious installer behavior.

Confidence: 94%Severity: 88%
SecurityMEDIUM
references/ntlm-relay.md

The fragment is a detailed NTLM relay and Active Directory attack guide. It contains no package implementation code, but the described commands directly facilitate credential capture, remote code execution, administrator-account creation, hash dumping, LDAP/RBCD privilege escalation, and password cracking. It should be treated as high-risk offensive content and not used against systems without explicit authorization.

Confidence: 99%Severity: 99%
Audit Metadata
Analyzed At
Sep 15, 2026, 09:59 AM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fresponder%2F@720207295ebb0a62b79c96a66ed82e965bed97bbe1a6ccaad5f81cdc77a3f387
Security Audit — socket — responder