certify

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

High-risk offensive security skill. Its stated purpose openly includes AD CS exploitation and privilege escalation, and it documents a full attack chain from template discovery to certificate abuse and Kerberos ticket injection. The biggest trust issue is the unverifiable Certify.exe assumption: GhostPack does not publish official Certify binaries, and the skill's binary/runtime claims do not match upstream documentation. This is not confirmed malware, but it is a dangerous AI-agent skill with strong exploit capability and significant supply-chain risk.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Apr 16, 2026, 08:21 PM
Package URL
pkg:socket/skills-sh/AeonDave%2Fmalskill%2Fcertify%2F@6b00cad046f3bbc0327cb605a4f0e3031e45cb63
Security Audit — socket — certify