executing-active-directory-attack-simulation

Warn

Audited by Socket on Aug 27, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its stated purpose matches its capabilities, but the purpose itself is offensive: it teaches an AI agent to perform credential theft, lateral movement, ticket forgery, and domain compromise steps. There is no clear exfiltration endpoint or deceptive credential proxying, so this is not confirmed malware, but it is a high-risk penetration-testing skill that should be tightly restricted or blocked for general agent use.

Confidence: 91%Severity: 86%
AnomalyLOW
references/api-reference.md

No direct evidence of malware or intentional sabotage is present in the supplied documentation. It describes dual-use Active Directory reconnaissance and attack-simulation functionality. The plaintext password in the example is a credential-handling warning, and the described techniques require explicit authorization. The implementation must be reviewed separately to assess actual network, filesystem, and credential-handling behavior.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Aug 27, 2026, 07:38 AM
Package URL
pkg:socket/skills-sh/galyarderlabs%2Fgalyarder-framework%2Fexecuting-active-directory-attack-simulation%2F@8b640288dd8184b39d940a50549ac3d424dd2441df3a8a881a86aee5994d8d7e
Security Audit — socket — executing-active-directory-attack-simulation