windows-privilege-escalation

Fail

Audited by Socket on Jul 21, 2026

3 alerts found:

SecurityMalwarex2
SecurityMEDIUM
SKILL.md

High-risk offensive security skill. Its capabilities align with its stated purpose, but that purpose is to help an AI agent perform Windows privilege escalation, credential access, and post-exploitation while also chaining into other attack skills. No clear hidden exfiltration or obfuscation is present, so this is not confirmed malware, but it is dangerous and inappropriate for general agent deployment.

Confidence: 94%Severity: 93%
MalwareHIGH
UAC_BYPASS_METHODS.md

This module is highly indicative of malicious exploitation/privilege-escalation tooling. It provides actionable UAC bypass and auto-elevation abuse instructions using trusted Windows binaries, manipulates HKCU registry keys to redirect elevated execution, performs DLL hijacking-style file placement, triggers elevated scheduled tasks (DiskCleanup/SilentCleanup), and includes an INF example referencing a remote attacker-controlled HTTP payload. In a supply-chain context, it should be treated as dangerous and not as legitimate dependency code.

Confidence: 92%Severity: 98%
MalwareHIGH
TOKEN_POTATO_TRICKS.md

This fragment is high-risk and strongly malicious instructional content. It provides an actionable Windows privilege-escalation and credential-theft playbook: obtain SYSTEM-level execution via token impersonation (“Potato” family and related coercion paths), then extract SAM/SYSTEM/SECURITY hives and NTDS.dit using backup semantics for offline credential dumping. It further includes guidance for driver-loading/kernel exploitation steps. No defensive or benign software functionality is present in this module.

Confidence: 94%Severity: 98%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:29 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fwindows-privilege-escalation%2F@f4fed248ec337b10b27255640f812df504c0c1cf050a04815b956c825b18e0d0
Security Audit — socket — windows-privilege-escalation