abusing-dpapi-for-credential-access

Fail

Audited by Socket on Aug 3, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

High-risk offensive red-team skill. Its capabilities are aligned with its stated purpose, and tooling provenance is mostly legitimate, but the purpose itself is credential theft/post-exploitation at scale, including browser/session hijack material and domain-wide DPAPI decryption. This is not confirmed malware, but it is a dangerous AI-agent capability and should be classified as suspicious/high-risk.

Confidence: 95%Severity: 93%
MalwareHIGH
scripts/agent.py

This module is a high-risk credential-access/forensic helper that enumerates Windows DPAPI master key and related credential/Vault artifacts from a mounted profile and can decrypt/triage them by invoking external DPAPI decryption tools. It accepts plaintext passwords and NTLM hashes, forwards them to subprocesses as command-line arguments, and prints captured outputs that may contain decrypted secrets or sensitive metadata. While no network exfiltration is present in this snippet, its functionality is directly aligned with credential theft/unauthorized secret recovery, making it unsuitable as a general-purpose supply-chain dependency.

Confidence: 74%Severity: 84%
Audit Metadata
Analyzed At
Aug 3, 2026, 03:42 AM
Package URL
pkg:socket/skills-sh/mukul975%2Fanthropic-cybersecurity-skills%2Fabusing-dpapi-for-credential-access%2F@5b5e4e0b20a8d48a4704b398b91fddec7c41c0f6153f8f89ac04ae84c9ef4540
Security Audit — socket — abusing-dpapi-for-credential-access