ntlm-relay-coercion

Fail

Audited by Socket on Sep 15, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK. The skill is internally consistent as an offensive security playbook, but its purpose is to equip the agent with credential-relay, coercion, and privilege-escalation tradecraft against Windows/AD targets. The main risk is not hidden exfiltration but explicit attack enablement and expansion into additional offensive skills.

Confidence: 94%Severity: 92%
MalwareHIGH
COERCION_METHODS.md

This fragment is not benign dependency code; it is highly actionable offensive guidance for Windows/Active Directory authentication coercion and NTLM relay-based privilege escalation. It explicitly details coercion RPC interfaces, attacker-controlled listener/relay usage, and high-impact AD outcomes. As a supply-chain component (e.g., bundled in an npm/RPM package), it would represent a serious misuse risk and should be treated as malicious/abusive content rather than legitimate functionality.

Confidence: 86%Severity: 100%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:16 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fntlm-relay-coercion%2F@a9f298b9861ce72d1c7f6f6b2418f592015d63b6be75100a8850dfe5091c739c
Security Audit — socket — ntlm-relay-coercion