ad-dacl-abuse

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent as a pentest technique, but it equips an AI agent with explicit offensive AD abuse procedures including password resets, ACL rewrites, DCSync, hash dumping, and GPO-based RCE. There is no evidence of covert third-party credential harvesting, so this is not confirmed malware, but it is a high-risk exploit skill.

Confidence: 96%Severity: 93%
Audit Metadata
Analyzed At
Sep 20, 2026, 11:03 PM
Package URL
pkg:socket/skills-sh/noorqureshi%2Fsploitagent%2Fad-dacl-abuse%2F@310a23ad5566121d36035f08d932f4857d86737271fefa24b42028b208242e0c
Security Audit — socket — ad-dacl-abuse