network-protocol-attacks
Audited by Socket on Sep 15, 2026
2 alerts found:
SecurityMalwareSUSPICIOUS. The install source evidence is mostly coherent and official enough for the named tools, so this is not confirmed malware or a credential-harvesting lure. However, the skill’s stated purpose is explicitly offensive: it equips an AI agent with network attack, credential capture/relay, segmentation bypass, and evasion procedures, which makes it a high-risk security/exploit skill even without deceptive data exfiltration or malicious installers.
The provided file content is an attacker-focused playbook for network poisoning, NTLM credential capture, NTLM relay, and Active Directory compromise (RBCD/shadow credentials/ADCS), including offline cracking facilitation and post-exploitation secrets dumping. It contains multiple explicit indicators of malicious operational intent (credential theft, relay orchestration, and privilege escalation chaining). No benign or safety-preserving use case is evident in the fragment.