ad-adcs
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides command-line examples for executing tools such as
certipyfor enumeration (certipy find), certificate requests (certipy req), and authentication (certipy auth). - [PRIVILEGE_ESCALATION]: The core purpose of the skill is to guide a penetration tester through escalating privileges from a standard user to a Domain Administrator by exploiting misconfigured certificate templates.
- [PERSISTENCE]: The skill notes that stolen Certificate Authority (CA) keys or machine certificates can be used as persistence mechanisms to survive password resets.
- [INDIRECT_PROMPT_INJECTION]: The skill describes a workflow that involves reading output from external tools like
certipy findto identify attack paths. This presents a theoretical ingestion surface for untrusted data from the target environment. - Ingestion points: Tool output from
certipy findprocessed in the shell. - Boundary markers: None present in the provided instructions.
- Capability inventory: The skill uses shell command execution via tools like
certipyandbloodhound(SKILL.md). - Sanitization: None described for the processing of tool output.
Audit Metadata