windows-ad

Warn

Audited by Socket on Jul 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent with its stated purpose, but that purpose is to equip an AI agent for offensive Active Directory operations, including credential theft and relay/coercion techniques. There is no clear malicious deception or exfiltration endpoint in the text, so this is not confirmed malware, but it is a high-risk security skill by design.

Confidence: 90%Severity: 86%
Audit Metadata
Analyzed At
Jul 18, 2026, 08:18 AM
Package URL
pkg:socket/skills-sh/zhaoxuya520%2Freverse-skill%2Fwindows-ad%2F@55a4581fd4027f4aa2a61a4f2bce7e21cd0377590a5a7790b7d812ba1fb14354
Security Audit — socket — windows-ad