skills/aeondave/malskill/certipy/Gen Agent Trust Hub

certipy

Warn

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains a large collection of shell commands designed to be executed in an Active Directory environment. These commands perform network enumeration, manipulate domain objects, and initiate authentication attempts.
  • [PRIVILEGE_ESCALATION]: The primary function of the skill is to document and facilitate privilege escalation within Active Directory. It provides step-by-step guides for exploiting ADCS misconfigurations to escalate from a standard domain user to a Domain Administrator.
  • [EXTERNAL_DOWNLOADS]: The instructions direct the user to install the certipy-ad package and reference the use of external scripts such as coercer.py, PetitPotam.py, and secretsdump.py. These tools are not provided within the skill package and are referenced without version pinning or integrity validation.
  • [CREDENTIALS_UNSAFE]: The skill documentation frequently provides command examples that require passing sensitive credentials, including plaintext passwords and NTLM hashes, as command-line arguments. This practice results in sensitive data being exposed in process listings and shell history files.
  • [DATA_EXFILTRATION]: The skill describes methods for harvesting NTLM hashes from privileged accounts, such as Domain Controllers and Administrators, through PKINIT authentication mechanisms and PAC extraction techniques.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — certipy