Book a 30-minute demo →
Skill scan report

windows-ad

View on GitHub
24 Low Automated analysis flagged 2 potential risk patterns.

What this skill does

This skill is a security/teaching tool focused on authorized Active Directory and Windows identity attacks, including Kerberos, AD CS, BloodHound paths, NTLM relay, and domain privilege escalation res

github/zhaoxuya520 - teaching/educational content - 23.3k stars

Threatsteaching/educational content tool usage guidance

Threat analysis

teaching/educational content1 finding
tool usage guidance1 finding

Skill info

Namezhaoxuya520/windows-ad
Registrygithub
Versioncf745b8
PURLpkg:github/zhaoxuya520/reverse-skill@cf745b8?skill=windows-ad
Stars23.3k

Assessments (2)

teaching/educational content1 finding HIGH
HIGH

teaching/educational content via local-llm-review

SKILL.md

The skill contains detailed instructions on using tools like Mimikatz, BloodHound, and Certipy for AD attacks. These are explicitly described as teaching material for authorized red-team operations, n
tool usage guidance1 finding MEDIUM
MEDIUM

tool usage guidance via local-llm-review

SKILL.md

The skill includes guidance on using tools like ntlmrelayx and Responder for NTLM relay attacks. These are described as requiring explicit authorization and are part of the educational content, not ex

Badge

Add the Anomity scan badge for windows-ad to your README.

Anomity Skill Check badge

Markdown
[![Anomity Skill Check](https://anomity.ai/skills/badge.svg)](https://anomity.ai/skills/github/zhaoxuya520/windows-ad/)
HTML
<a href="https://anomity.ai/skills/github/zhaoxuya520/windows-ad/"><img src="https://anomity.ai/skills/badge.svg" alt="Anomity Skill Check"></a>
Image URL
https://anomity.ai/skills/badge.svg

How Anomity governs this at runtime

Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.

Book a 30-minute demo to see your own skill inventory.

Methodology and disputes

Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of windows-ad? Report an issue or request a rescan.

Ask AI about Anomity
ChatGPT Claude Perplexity Google AI Grok