ntlm-relay-coercion
Audited by Socket on Jul 21, 2026
2 alerts found:
SecurityMalwareSUSPICIOUS/HIGH-RISK skill. It is internally consistent as an offensive NTLM relay playbook, but it gives an AI agent concrete attack procedures, privilege-escalation paths, and transitive loading of adjacent attack skills. The main issue is not deception; it is that the skill meaningfully equips an agent for active intrusion against real targets.
This fragment is not benign dependency code; it is highly actionable offensive guidance for Windows/Active Directory authentication coercion and NTLM relay-based privilege escalation. It explicitly details coercion RPC interfaces, attacker-controlled listener/relay usage, and high-impact AD outcomes. As a supply-chain component (e.g., bundled in an npm/RPM package), it would represent a serious misuse risk and should be treated as malicious/abusive content rather than legitimate functionality.