m365-entra-attack

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

High-risk offensive security skill. Its attack, enumeration, and credential-validation capabilities are aligned with its stated red-team purpose, but that purpose itself gives an AI agent powerful real-world intrusion functionality. No clear third-party credential exfiltration or malware behavior is shown, yet TLS bypasses, autonomous auth attempts, and attack-skill chaining make the overall risk high.

Confidence: 94%Severity: 90%
Audit Metadata
Analyzed At
Aug 27, 2026, 05:32 AM
Package URL
pkg:socket/skills-sh/xiaolai%2Fclaude-bughunter%2Fm365-entra-attack%2F@bc8f4331c9e5826abed4a62813e38d3cd45a03ce89c073005cd537f11931ce4b
Security Audit — socket — m365-entra-attack