ntlm-relay-coercion
Audited by Socket on Sep 15, 2026
2 alerts found:
SecurityMalwareSUSPICIOUS/HIGH-RISK. The skill is internally consistent as an offensive security playbook, but its purpose is to equip the agent with credential-relay, coercion, and privilege-escalation tradecraft against Windows/AD targets. The main risk is not hidden exfiltration but explicit attack enablement and expansion into additional offensive skills.
This fragment is not benign dependency code; it is highly actionable offensive guidance for Windows/Active Directory authentication coercion and NTLM relay-based privilege escalation. It explicitly details coercion RPC interfaces, attacker-controlled listener/relay usage, and high-impact AD outcomes. As a supply-chain component (e.g., bundled in an npm/RPM package), it would represent a serious misuse risk and should be treated as malicious/abusive content rather than legitimate functionality.