network-protocol-attacks

Fail

Audited by Socket on Sep 15, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The install source evidence is mostly coherent and official enough for the named tools, so this is not confirmed malware or a credential-harvesting lure. However, the skill’s stated purpose is explicitly offensive: it equips an AI agent with network attack, credential capture/relay, segmentation bypass, and evasion procedures, which makes it a high-risk security/exploit skill even without deceptive data exfiltration or malicious installers.

Confidence: 95%Severity: 86%
MalwareHIGH
NAME_RESOLUTION_POISONING.md

The provided file content is an attacker-focused playbook for network poisoning, NTLM credential capture, NTLM relay, and Active Directory compromise (RBCD/shadow credentials/ADCS), including offline cracking facilitation and post-exploitation secrets dumping. It contains multiple explicit indicators of malicious operational intent (credential theft, relay orchestration, and privilege escalation chaining). No benign or safety-preserving use case is evident in the fragment.

Confidence: 90%Severity: 100%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:16 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fnetwork-protocol-attacks%2F@0ec1dfe54cf2d74be4f61741f101233178f51a60bdf47e464b0c65e8f69cbded
Security Audit — socket — network-protocol-attacks