CtrlK
BlogDocsLog inGet started
Tessl Logo

ad-certipy-esc-chain

ADCS abuse via Certipy — find vulnerable templates (ESC1-ESC15), request a certificate, authenticate as the target, dump the krbtgt. Full chain in 4 commands. Covers ESC1 (any SAN), ESC2 (any-purpose EKU), ESC3 (enrollment-agent), ESC4 (vulnerable ACL), ESC8 (NTLM relay to CA), ESC9/10/11/13.

63

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/ad/certipy-esc-chain/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

76%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-structured offensive-security skill with copy-paste commands and a clear ESC reference catalog. Its main gap is the absence of explicit validation checkpoints in a destructive compromise chain, which caps workflow clarity.

Suggestions

Add explicit validation/verification gates between destructive steps (e.g. 'Verify administrator.pfx was written' before auth, 'Confirm TGT/NT hash obtained' before DCSync) to lift workflow_clarity above the 3 cap.

Move the per-ESC exploit details (ESC8, ESC9/10 chains) into a separate reference file and link to it from a concise SKILL.md overview to improve progressive_disclosure.

Trim opinion prose ('the single best tool for ADCS attack') to nudge conciseness toward 5.

DimensionReasoningScore

Conciseness

Mostly lean, command-driven content where nearly every token earns its place (dense ESC catalog table, copy-paste blocks); minor prose that could be trimmed such as 'the single best tool for ADCS attack' and the OPSEC commentary.

4 / 5

Actionability

Fully executable, copy-paste-ready certipy/impacket commands with annotated expected output covering the common cases (ESC1 chain, ESC8 relay, ESC9/10 UPN abuse).

5 / 5

Workflow Clarity

A clear numbered 1-5 sequence exists with implicit checkpoints via output comments, but this destructive domain-compromise skill has no explicit validation/verification gates before proceeding (e.g. verify the PFX was issued, verify auth succeeded before DCSync), so workflow clarity is capped at 3 per the rubric.

3 / 5

Progressive Disclosure

Well-organized into clearly signaled sections (find, ESC catalog, ESC1/ESC8/ESC9-10 chains, OPSEC, References); no bundle files exist to verify references against. Some inlined content (full ESC catalog plus multiple chain variants) could be split into reference files, keeping this just below 5.

4 / 5

Total

16

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, well-scoped description with concrete actions and distinct trigger vocabulary, but it omits an explicit 'Use when...' trigger clause, which limits completeness. Adding a one-line usage-trigger sentence would raise it.

Suggestions

Add an explicit 'Use when ...' clause (e.g. 'Use when attacking Active Directory Certificate Services / ADCS, or when the user mentions ESC1-ESC15, vulnerable cert templates, or Certipy.') to satisfy the completeness 'when' requirement.

Include a couple of natural synonyms users say ('PKI', 'certificate services', 'golden ticket') to broaden trigger_term_quality.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'find vulnerable templates (ESC1-ESC15)', 'request a certificate', 'authenticate as the target', 'dump the krbtgt' — plus an enumerated ESC1-15 breakdown, giving comprehensive coverage of capabilities.

5 / 5

Completeness

The 'what' is clear ('Full chain in 4 commands' with the four steps named), but there is no explicit 'Use when...' / 'when should Claude use it' clause, which caps completeness at 3 per the rubric guideline.

3 / 5

Trigger Term Quality

Strong domain-natural keywords ('ADCS', 'Certipy', 'ESC1...ESC15', 'NTLM relay', 'krbtgt') but missing a few common synonyms a user might say (e.g. 'PKI', 'certificate services', 'golden ticket').

4 / 5

Distinctiveness Conflict Risk

A clear niche (ADCS abuse via Certipy with specific ESC references) with distinct triggers and minimal overlap risk against other skills.

5 / 5

Total

17

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.