exploiting-adcs-with-certipy

Warn

Audited by Socket on Aug 4, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent and uses legitimate install sources, but its actual purpose is to equip an AI agent with offensive AD CS exploitation workflows that can produce Domain Admin compromise, credential recovery, and persistence. No clear malware or deceptive data-routing is present, but the exploit-focused capability and credential forwarding make it a high-risk security skill.

Confidence: 91%Severity: 86%
SecurityMEDIUM
references/api-reference.md

This fragment is documentation only and contains no executable logic to evaluate for supply-chain sabotage, hidden backdoors, or exfiltration. However, it clearly describes the tool’s intended offensive capabilities against AD CS (enumeration, certificate template abuse, NTLM relay to enrollment endpoints, shadow credentials, and certificate/key forging). Treat the broader dependency as high dual-use risk: allowlist and constrain usage, require authorization controls, and perform deeper code-level review of the actual implementation for any unexpected behavior beyond the documented functionality.

Confidence: 62%Severity: 70%
Audit Metadata
Analyzed At
Aug 4, 2026, 02:42 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fexploiting-adcs-with-certipy%2F@ba227cc03eaa204ddf2b484092728bd89930b1d3b7372ed26ee566b3115c9160
Security Audit — socket — exploiting-adcs-with-certipy