active-directory-acl-abuse

Warn

Audited by Socket on Jul 21, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

High-risk offensive security skill. Its capabilities are internally consistent with its stated purpose, but that purpose is to help an AI agent conduct AD exploitation, credential compromise, and privilege escalation, including chaining into additional offensive skills. No strong malware or exfiltration indicators are present, but the operational security risk is very high.

Confidence: 96%Severity: 92%
SecurityMEDIUM
BLOODHOUND_PATHS.md

This fragment is not a benign library module; it is an offensively oriented BloodHound/BloodHound CE workflow that combines credentialed AD data collection and authenticated API retrieval with Cypher queries that return actionable privilege-escalation and lateral-movement paths (Domain Admin reachability, DCSync/Kerberoasting/AS-REP roast chains, GPO abuse, unconstrained delegation, LAPS readers). No obfuscated payloads or in-process malware are present in the snippet itself, but its misuse potential is extremely high and it should be treated as high risk in any software supply-chain context.

Confidence: 78%Severity: 92%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:25 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Factive-directory-acl-abuse%2F@a39f748ed307add7f376b5fc12073446306d565ce9ac148698a73dc2b920ac40
Security Audit — socket — active-directory-acl-abuse