active-directory-acl-abuse
Fail
Audited by Snyk on Jul 21, 2026
Risk Level: CRITICAL
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill repeatedly shows commands and examples that embed plaintext credentials (e.g., user:password, -p pass, explicit example passwords), which forces an LLM to output secret values verbatim and is therefore insecure.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This content is an explicit offensive AD ACL abuse playbook: it provides step-by-step commands and tools for credential theft (DCSync/secretsdump/Mimikatz), persistence (shadow credentials, RBCD, GPO abuse), privilege escalation (WriteDACL/WriteOwner/AddMember), and stealthy reconnaissance — clearly intended to enable malicious abuse of Active Directory.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill is an explicit offensive Active Directory playbook that instructs the agent to change passwords, modify AD object ACLs, add accounts to privileged groups, write GPOs (adding local admins/scheduled tasks), perform DCSync and shadow-credential attacks—actions that directly modify the state of remote hosts and domain controllers and thus can compromise the machine/domain state.
Issues (3)
W007
HIGHInsecure credential handling detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata