ad-dacl-abuse
Warn
Audited by Socket on Sep 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent as a pentest technique, but it equips an AI agent with explicit offensive AD abuse procedures including password resets, ACL rewrites, DCSync, hash dumping, and GPO-based RCE. There is no evidence of covert third-party credential harvesting, so this is not confirmed malware, but it is a high-risk exploit skill.
Confidence: 96%Severity: 93%
Audit Metadata