certipy
Audited by Socket on Sep 5, 2026
2 alerts found:
SecurityMalwareSUSPICIOUS/HIGH-RISK skill: the install path is coherent and relatively trustworthy, and the capabilities match the stated purpose, but that stated purpose is to equip an AI agent with offensive AD CS exploitation workflows. It enables credential use, relay, privilege escalation, directory/CA modification, and domain-compromise actions, which is disproportionate for a general agent skill and creates significant abuse potential even without clear malware or hidden exfiltration.
The provided fragment is strongly malicious/adversary-oriented content rather than benign software functionality. It offers an end-to-end workflow to abuse AD CS and Kerberos PKINIT to impersonate principals, extract NT hash material without knowing passwords, optionally modify directory attributes for persistence (shadow credentials), and use derived hashes for further credential dumping against domain controllers. No supply-chain/library code behavior is present to evaluate beyond the explicit attack procedures; risk is driven entirely by the clear credential theft and privilege escalation intent.