competition-dpapi-credential-chain

Warn

Audited by Socket on Jul 30, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent, but its purpose is offensive credential recovery and replay of Windows/DPAPI secrets. It shows no clear exfiltration or malicious installer behavior, yet it meaningfully equips an AI agent for credential theft-style activity, so overall risk is high while malware confidence remains low.

Confidence: 87%Severity: 72%
AnomalyLOW
references/dpapi-credential-chain.md

No executable software behavior is present; the fragment is a DPAPI credential-decryption/reuse checklist. Nonetheless, its outcome-driven focus on recovering plaintext secrets and validating usable access (SMB/RDP/WinRM, session/app login) makes the content strongly suspicious and potentially enabling for credential theft. Treat as high-risk content if found inside a dependency or distribution artifact.

Confidence: 72%Severity: 65%
Audit Metadata
Analyzed At
Jul 30, 2026, 12:52 PM
Package URL
pkg:socket/skills-sh/zhaoxuya520%2Fai-fullstack-delivery-workflow%2Fcompetition-dpapi-credential-chain%2F@79c1d19879f0828b315024d1b34059aa5b57ea0d2610df0e29feed90340df7b9
Security Audit — socket — competition-dpapi-credential-chain