ntwarden-windows-analysis-toolkit

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent as a Windows kernel/user-mode research toolkit, but its footprint is high-risk: admin execution, kernel driver installation, weakened boot security settings, kernel memory access, and an unauthenticated remote inspection server. The main concern is dangerous capability and insecure remote/data-plane design, not clear credential theft or confirmed malware.

Confidence: 89%Severity: 84%
Audit Metadata
Analyzed At
Apr 14, 2026, 04:34 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fntwarden-windows-analysis-toolkit%2F@1c0e33a85dc5419342c1b1b1c1632d2c4422a1af