executing-active-directory-attack-simulation
Audited by Socket on Aug 27, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS/HIGH-RISK skill. Its stated purpose matches its capabilities, but the purpose itself is offensive: it teaches an AI agent to perform credential theft, lateral movement, ticket forgery, and domain compromise steps. There is no clear exfiltration endpoint or deceptive credential proxying, so this is not confirmed malware, but it is a high-risk penetration-testing skill that should be tightly restricted or blocked for general agent use.
No direct evidence of malware or intentional sabotage is present in the supplied documentation. It describes dual-use Active Directory reconnaissance and attack-simulation functionality. The plaintext password in the example is a credential-handling warning, and the described techniques require explicit authorization. The implementation must be reviewed separately to assess actual network, filesystem, and credential-handling behavior.