Active Directory Attacks

Fail

Audited by Snyk on May 27, 2026

Risk Level: CRITICAL
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The prompt repeatedly embeds plaintext credentials, hashes, and secret placeholders directly into command examples (e.g., -u 'user' -p 'password', domain/user:password, admin:password, KRBTGT_HASH, NTHASH), which requires the LLM to handle or output secret values verbatim and therefore poses high exfiltration risk.

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). This document is an explicit offensive playbook containing step‑by‑step instructions and tooling to steal credentials (Kerberoast, AS‑REP, DCSync, Mimikatz), forge/plant Kerberos tickets (Golden/Silver Tickets), perform NTLM relays and certificate/ADCS abuses, and deploy persistent backdoors (via SCCM/WSUS, GPO abuse, RBCD), which together constitute deliberate malicious activity and supply‑chain/persistence capabilities.

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill explicitly instructs running privileged system-changing commands (e.g., "sudo date -s" to change system time) and contains multiple offensive actions that modify remote/host state (credential extraction, DCSync, Golden Ticket creation, restoring DC passwords) which push the agent to perform privileged or state-changing operations.

Issues (3)

W007
HIGH

Insecure credential handling detected in skill instructions.

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
May 27, 2026, 10:14 PM
Issues
3
Security Audit — snyk — Active Directory Attacks