ad-pentest

Warn

Audited by Socket on May 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its capabilities are internally consistent with its stated purpose, but that purpose is to provide an AI agent with offensive AD pentesting procedures including credential capture, relay, lateral movement, and escalation. Install sources are mostly recognizable and not strongly deceptive, so this is not confirmed malware; however, as an AI agent skill it meaningfully increases offensive capability and handles sensitive credentials and hashes, making the overall security risk high.

Confidence: 94%Severity: 90%
Audit Metadata
Analyzed At
May 9, 2026, 03:51 AM
Package URL
pkg:socket/skills-sh/woohyun212%2Fsecurity-skill%2Fad-pentest%2F@49fbe0c4c62849c2e6c9365fd04640353478a412
Security Audit — socket — ad-pentest