ntlm-relay-coercion

Fail

Audited by Socket on Jul 21, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. It is internally consistent as an offensive NTLM relay playbook, but it gives an AI agent concrete attack procedures, privilege-escalation paths, and transitive loading of adjacent attack skills. The main issue is not deception; it is that the skill meaningfully equips an agent for active intrusion against real targets.

Confidence: 95%Severity: 94%
MalwareHIGH
COERCION_METHODS.md

This fragment is not benign dependency code; it is highly actionable offensive guidance for Windows/Active Directory authentication coercion and NTLM relay-based privilege escalation. It explicitly details coercion RPC interfaces, attacker-controlled listener/relay usage, and high-impact AD outcomes. As a supply-chain component (e.g., bundled in an npm/RPM package), it would represent a serious misuse risk and should be treated as malicious/abusive content rather than legitimate functionality.

Confidence: 86%Severity: 100%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:26 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fntlm-relay-coercion%2F@a9f298b9861ce72d1c7f6f6b2418f592015d63b6be75100a8850dfe5091c739c
Security Audit — socket — ntlm-relay-coercion