exploiting-active-directory-with-bloodhound

Warn

Audited by Socket on Apr 6, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
scripts/agent.py

No clear evidence of stealthy malware in the provided module. The code primarily enables dual-use Active Directory recon/attack-path analysis by executing SharpHound/bloodhound-python, parsing exported JSON, and optionally executing arbitrary Cypher against Neo4j. The main security concerns are misuse potential and operational risks: passing plaintext passwords as CLI arguments to subprocesses, PATH-dependent external binary execution, hardcoded default Neo4j credentials, unrestricted user-controlled Cypher execution (data/DoS risk), and writing reports to an arbitrary output path. This dependency should be used only in tightly controlled, authorized environments with appropriate access controls and hardening (pin executable paths, restrict who can set --cypher-query/--output, and avoid default credentials/CLI password exposure).

Confidence: 66%Severity: 63%
SecurityMEDIUM
SKILL.md

High-risk offensive security skill. Its capabilities are internally consistent with a red-team BloodHound guide, but it equips an AI agent to perform AD reconnaissance, data exfiltration, and exploitation planning against real environments. No clear credential-harvesting or deceptive exfiltration endpoint is present, so this is better classified as a dangerous offensive skill rather than malware.

Confidence: 90%Severity: 86%
Audit Metadata
Analyzed At
Apr 6, 2026, 03:47 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fexploiting-active-directory-with-bloodhound%2F@5bf4f18630897666f35bca66588a43741060a77b
Security Audit — socket — exploiting-active-directory-with-bloodhound