kerberos-pentesting

Warn

Audited by Socket on Aug 12, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

该 Skill 与其声明目的基本一致,但其目的本身就是面向 AI Agent 的 Kerberos 攻击与后渗透操作。未见明显隐蔽安装器或第三方凭据中转,但其能力覆盖凭据提取、票据伪造、委派滥用和远程访问,属于高风险进攻性安全 Skill,应归类为可疑且危险的攻击辅助内容而非普通开发/管理技能。

Confidence: 89%Severity: 89%
SecurityMEDIUM
references/kerberos-attacks.md

No executable code or runtime malicious behavior is present in this fragment; however, it is highly actionable offensive guidance for Kerberos/Active Directory credential-access and authentication-bypass (enumeration, roasting, ticket forging, delegation abuse, and pass-the-ticket), including installation/use of exploitation tooling. In a supply-chain context, this represents a serious high-abuse content risk rather than code-level malware evidence.

Confidence: 66%Severity: 85%
Audit Metadata
Analyzed At
Aug 12, 2026, 03:34 AM
Package URL
pkg:socket/skills-sh/wgpsec%2Faboutsecurity%2Fkerberos-pentesting%2F@438dc94dfd7139c4c8b598a2021cf08ac002aacb449996dc5868885125e77cd9
Security Audit — socket — kerberos-pentesting