certipy

Fail

Audited by Socket on Sep 5, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill: the install path is coherent and relatively trustworthy, and the capabilities match the stated purpose, but that stated purpose is to equip an AI agent with offensive AD CS exploitation workflows. It enables credential use, relay, privilege escalation, directory/CA modification, and domain-compromise actions, which is disproportionate for a general agent skill and creates significant abuse potential even without clear malware or hidden exfiltration.

Confidence: 94%Severity: 84%
MalwareHIGH
references/adcs-internals-and-detection.md

The provided fragment is strongly malicious/adversary-oriented content rather than benign software functionality. It offers an end-to-end workflow to abuse AD CS and Kerberos PKINIT to impersonate principals, extract NT hash material without knowing passwords, optionally modify directory attributes for persistence (shadow credentials), and use derived hashes for further credential dumping against domain controllers. No supply-chain/library code behavior is present to evaluate beyond the explicit attack procedures; risk is driven entirely by the clear credential theft and privilege escalation intent.

Confidence: 90%Severity: 100%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:46 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fcertipy%2F@b7a175dd11e84b8cb887d66eaf5fb3ced429d9fbebf3dccd0e102783eac5cb6d
Security Audit — socket — certipy