attacking-entra-id

Warn

Audited by Socket on Jul 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its capabilities are internally consistent with its stated pentesting purpose, so it is not deceptive malware, but it materially equips an AI agent to perform offensive cloud identity attacks, credential theft, token replay, and hybrid compromise. No hidden installer, covert exfiltration endpoint, or obfuscation is present, yet the operational impact is high enough to classify as a dangerous security skill.

Confidence: 94%Severity: 87%
Audit Metadata
Analyzed At
Jul 30, 2026, 01:20 AM
Package URL
pkg:socket/skills-sh/trilwu%2Fsecskills%2Fattacking-entra-id%2F@5a943c2a846a2231a26c865cca829dc234683f630f44aa3a42bf31fda002acf5
Security Audit — socket — attacking-entra-id