competition-dpapi-credential-chain
Audited by Socket on Jul 30, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS: the skill is internally coherent, but its purpose is offensive credential recovery and replay of Windows/DPAPI secrets. It shows no clear exfiltration or malicious installer behavior, yet it meaningfully equips an AI agent for credential theft-style activity, so overall risk is high while malware confidence remains low.
No executable software behavior is present; the fragment is a DPAPI credential-decryption/reuse checklist. Nonetheless, its outcome-driven focus on recovering plaintext secrets and validating usable access (SMB/RDP/WinRM, session/app login) makes the content strongly suspicious and potentially enabling for credential theft. Treat as high-risk content if found inside a dependency or distribution artifact.