Active Directory Attacks
Fail
Audited by Snyk on May 27, 2026
Risk Level: CRITICAL
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The prompt repeatedly embeds plaintext credentials, hashes, and secret placeholders directly into command examples (e.g., -u 'user' -p 'password', domain/user:password, admin:password, KRBTGT_HASH, NTHASH), which requires the LLM to handle or output secret values verbatim and therefore poses high exfiltration risk.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This document is an explicit offensive playbook containing step‑by‑step instructions and tooling to steal credentials (Kerberoast, AS‑REP, DCSync, Mimikatz), forge/plant Kerberos tickets (Golden/Silver Tickets), perform NTLM relays and certificate/ADCS abuses, and deploy persistent backdoors (via SCCM/WSUS, GPO abuse, RBCD), which together constitute deliberate malicious activity and supply‑chain/persistence capabilities.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill explicitly instructs running privileged system-changing commands (e.g., "sudo date -s" to change system time) and contains multiple offensive actions that modify remote/host state (credential extraction, DCSync, Golden Ticket creation, restoring DC passwords) which push the agent to perform privileged or state-changing operations.
Issues (3)
W007
HIGHInsecure credential handling detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata