adcs-persistence
Warn
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONCREDENTIALS_UNSAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides multiple pre-configured command lines for high-risk offensive tools like certipy, mimikatz, Rubeus, and ForgeCert.exe. It includes instructions for memory patching of crypto APIs and the use of sudo for time synchronization.\n- [CREDENTIALS_UNSAFE]: The skill contains procedures for harvesting the most sensitive secrets in an AD environment, including the CA private key, DPAPI masterkeys, and user/machine certificates.\n- [DATA_EXFILTRATION]: It instructs the agent to systematically move harvested security artifacts (PFX files, Kerberos tickets, and hashes) to a local storage directory for later retrieval.\n- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it interpolates untrusted user inputs directly into shell commands.\n
- Ingestion points: Target SIDs, IP addresses, and account names provided as CLI arguments in SKILL.md.\n
- Boundary markers: No boundary markers or warnings are used to separate user data from command templates.\n
- Capability inventory: The skill possesses extensive shell execution and file system access capabilities via integrated offensive tools.\n
- Sanitization: No input validation or escaping is applied to the interpolated variables.
Audit Metadata