network-protocol-attacks
Audited by Socket on Jul 21, 2026
2 alerts found:
SecurityMalwareHigh-risk offensive security skill. The content is internally consistent with its stated purpose, but that purpose is to help an AI agent execute network attacks, capture credentials, relay authentication, evade detection, and chain into further offensive skills. No confirmed malware or hidden exfiltration is present, but the skill is dangerous by design and should be classified as suspicious/high risk rather than benign.
The provided file content is an attacker-focused playbook for network poisoning, NTLM credential capture, NTLM relay, and Active Directory compromise (RBCD/shadow credentials/ADCS), including offline cracking facilitation and post-exploitation secrets dumping. It contains multiple explicit indicators of malicious operational intent (credential theft, relay orchestration, and privilege escalation chaining). No benign or safety-preserving use case is evident in the fragment.