ad-delegation-abuse
Warn
Audited by Socket on Sep 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The markdown itself is not executing hidden payloads, and the cited commands mostly reference well-known offensive security tools rather than obvious malware. But the skill’s stated purpose is to help an AI agent abuse Kerberos delegation, relay authentication, impersonate privileged users, dump secrets, and take over hosts in a live AD environment. That footprint is inherently high risk and disproportionate for general agent use, even if coherent with the offensive purpose.
Confidence: 92%Severity: 84%
Audit Metadata