active-directory-acl-abuse

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

This skill is internally consistent as an AD attack playbook, but its purpose is to help an AI agent perform offensive security operations: privilege escalation, credential dumping, password resets, ACL modification, and GPO abuse. There is no clear evidence of hidden malware or third-party credential theft, but it is a high-risk offensive capability set with moderate supply-chain concerns around the outdated BloodHound package reference and added risk from chaining into other skills.

Confidence: 94%Severity: 92%
SecurityMEDIUM
BLOODHOUND_PATHS.md

This fragment is not a benign library module; it is an offensively oriented BloodHound/BloodHound CE workflow that combines credentialed AD data collection and authenticated API retrieval with Cypher queries that return actionable privilege-escalation and lateral-movement paths (Domain Admin reachability, DCSync/Kerberoasting/AS-REP roast chains, GPO abuse, unconstrained delegation, LAPS readers). No obfuscated payloads or in-process malware are present in the snippet itself, but its misuse potential is extremely high and it should be treated as high risk in any software supply-chain context.

Confidence: 78%Severity: 92%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:14 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Factive-directory-acl-abuse%2F@a39f748ed307add7f376b5fc12073446306d565ce9ac148698a73dc2b920ac40
Security Audit — socket — active-directory-acl-abuse