performing-active-directory-compromise-investigation

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose is coherent for an AD compromise investigation guide, and the skill itself does not contain explicit download-execute commands, credential exfiltration, or third-party proxy data flows. However, it guides an AI agent in offensive-security-adjacent investigation activity, references high-risk credential-focused tools, and contemplates access to extremely sensitive AD artifacts. As a documentation skill it is not clearly malicious, but its security domain and potential use in offensive operations make it higher risk than ordinary reference content.

Confidence: 90%Severity: 58%
Audit Metadata
Analyzed At
Apr 6, 2026, 11:39 AM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fperforming-active-directory-compromise-investigation%2F@887b54d0545cd244236df698cce9651bbc204f9d