coercing-authentication-with-coercer-petitpotam

Warn

Audited by Socket on Aug 6, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its purpose and capabilities are internally consistent for red-team use, and the install sources are mostly legitimate, but it explicitly equips an AI agent to execute offensive AD coercion/relay chains leading to domain compromise. This is not confirmed malware, but it is a high-risk exploit skill with meaningful operational danger.

Confidence: 93%Severity: 84%
AnomalyLOW
scripts/agent.py

No direct malware is implemented in this Python fragment (no obfuscation, no persistence, no built-in exfiltration). However, it is a dual-use orchestrator that runs offensive authentication coercion tooling and accepts credentials. It increases practical risk by (1) echoing the full command line including passwords to stdout, and (2) executing binaries/scripts resolved from PATH (no integrity validation). Treat as high-risk for misuse and for secret-handling in operational environments; real malicious impact would depend on the external 'coercer' and PetitPotam.py code or on PATH/script substitution.

Confidence: 74%Severity: 60%
Audit Metadata
Analyzed At
Aug 6, 2026, 05:43 AM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fcoercing-authentication-with-coercer-petitpotam%2F@348d73c6e315d7e343d30a6d73db4cf12d2c947a52e4a2657dbe2298712957bd
Security Audit — socket — coercing-authentication-with-coercer-petitpotam