active-directory-acl-abuse

Fail

Audited by Snyk on Jul 21, 2026

Risk Level: CRITICAL
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill repeatedly shows commands and examples that embed plaintext credentials (e.g., user:password, -p pass, explicit example passwords), which forces an LLM to output secret values verbatim and is therefore insecure.

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). This content is an explicit offensive AD ACL abuse playbook: it provides step-by-step commands and tools for credential theft (DCSync/secretsdump/Mimikatz), persistence (shadow credentials, RBCD, GPO abuse), privilege escalation (WriteDACL/WriteOwner/AddMember), and stealthy reconnaissance — clearly intended to enable malicious abuse of Active Directory.

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill is an explicit offensive Active Directory playbook that instructs the agent to change passwords, modify AD object ACLs, add accounts to privileged groups, write GPOs (adding local admins/scheduled tasks), perform DCSync and shadow-credential attacks—actions that directly modify the state of remote hosts and domain controllers and thus can compromise the machine/domain state.

Issues (3)

W007
HIGH

Insecure credential handling detected in skill instructions.

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 21, 2026, 01:23 PM
Issues
3
Security Audit — snyk — active-directory-acl-abuse