Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add fatihkan/badi --skill pentest-adgit clone --depth 1 https://github.com/fatihkan/badiWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/fatihkan/badi/pentest-ad)<a href="https://agentmods.dev/skills/fatihkan/badi/pentest-ad"><img src="https://agentmods.dev/badge/skills/fatihkan/badi/pentest-ad/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/fatihkan/badi/pentest-ad"><img src="https://agentmods.dev/badge/skills/fatihkan/badi/pentest-ad.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 2 findings, up to high
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- high YARA Match · line 3 YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).Fix: Remove offensive tool references and exploit code. Legitimate agent skills should not contain penetration testing tools, exploit frameworks, or reconnaissance utilities.
- high Privilege Escalation · line 121 Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.Fix: Remove references to credential paths. Use environment variables or secrets managers. For docs, use placeholder paths (e.g., /path/to/config). Never load .env or token files in production code paths.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00076 | $0.01373 |
| Opus 5 | $0.00038 | $0.00687 |
| Sonnet 5 | $0.00015 | $0.00275 |
| Haiku 4.5 | $0.00008 | $0.00137 |
Grade A, and why
pentest-ad scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 139 lines — stays where its author put it; the contents beside it link to each section on GitHub.
pentest-ad
Internal pentest Active Directory advisory. BloodHound graph, Kerberos vulnerability classes, ACL abuse, lateral path. Live command composing requires a scope declaration.
Triggers
- "AD pentest"
- "BloodHound graph analysis"
- "I found a Kerberoast hash"
- "can I DCSync"
- "lateral movement plan"
- "Golden Ticket"
- "NTLM relay"
- "AD CS abuse"
Methodology Flow
1. Enum: SMB, LDAP, DNS, GPP (passive first)
2. Cred: kerbrute users -> AS-REP roasting (no preauth) -> hashcat
3. Foothold: low-priv shell (phish/web/initial)
4. Recon: BloodHound -> high-value path
5. Privesc: ACL abuse, Kerberos delegation, GPO modify
6. Lateral: PtH, PtT, NTLM relay, WinRM, RDP
7. DA: DCSync (Replicating Changes), Golden Ticket (offline)
8. Persistence: Skeleton key, AdminSDHolder (TIER 2, scope-required)
BloodHound Graph Analysis
If the user provides a BloodHound JSON export, the skill runs these queries (Cypher):
// Shortest path to Domain Admin from owned user
MATCH p=shortestPath((u:User {owned:true})-[*1..]->(g:Group {name:"DOMAIN ADMINS@DOMAIN"}))
RETURN p LIMIT 5
// Kerberoastable users with priv access
MATCH (u:User {hasspn:true})-[:MemberOf|AdminTo*1..]->(c:Computer)
WHERE u.enabled=true
RETURN u.name, c.name
// AS-REP roastable
MATCH (u:User {dontreqpreauth:true, enabled:true})
RETURN u.name, u.serviceprincipalnames
// Unconstrained delegation
MATCH (c:Computer {unconstraineddelegation:true})
RETURN c.name, c.distinguishedname
// GPO modify risk
MATCH (g:GPO)<-[:GenericAll|GenericWrite|WriteOwner|WriteDacl]-(u)
RETURN g.name, u.name
Common AD Vulnerability Classes
| Vulnerability | Detection | Impact |
|---|---|---|
| AS-REP roast | DONT_REQUIRE_PREAUTH flag |
Offline crackable hash |
| Kerberoast | User SPN + RC4 ticket | TGS hash crack -> service acc |
| Unconstrained delegation | Computer object flag | Compromise via the DC printer bug |
| NTLM relay | SMB sign off, web auth | Account takeover via relay |
| ACL abuse | GenericAll, WriteDacl | Reset password, add to group |
| ADCS ESC1-ESC8 | Vulnerable cert template | Domain admin via cert |
| LAPS read | ReadProperty ms-Mcs-AdmPwd | Local admin password leak |
| GPO modify | WriteProperty on GPO link | Mass policy compromise |
| Constrained delegation | Service can impersonate | DA via service abuse |
| MSSQL trustworthy | xp_cmdshell + sysadmin | SQL -> OS command |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 139 lines · 76 tokens per session scan A b6764d806517
pentest-ad is a skill published in the GitHub repository fatihkan/badi (7 stars, last pushed yesterday), licensed MIT. It adds 76 tokens to every session and 1,373 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-06.
Other skills, from other repositories
pr-triage
4-phase PR backlog management with audit, deep code review, validated comments, and optional worktree setup. Use when triaging pull requests, catching up on pending code reviews, or managing a backlog of open PRs. Args: 'all' to review all, PR numbers to focus (e.g. '42 57'), 'en'/'fr' for language, no arg = audit…
audit-agents-skills
Audit Claude Code agents, skills, and commands for quality and production readiness. Use when evaluating skill quality, checking production readiness scores, or comparing agents against best-practice templates.
eval-agents
Audit Claude Code agents defined in .claude/agents/ for description specificity, model tier appropriateness, tools scoping, and system prompt quality. Detects dispatch ambiguity between agents, flags over-permissive tool grants, and checks for human-in-the-loop patterns that break programmatic orchestration. Use when…
check-cache-bugs
Audit Claude Code setup for cache bugs (CC#40524): sentinel, --resume/--continue, attribution header + ArkNill B3/B4/B5.
issue-triage
3-phase issue backlog management with audit, deep analysis, and validated triage actions. Use when triaging GitHub issues, sorting bug reports, cleaning up stale tickets, or detecting duplicate issues. Args: 'all' to analyze all, issue numbers to focus (e.g. '42 57'), 'en'/'fr' for language, no arg = audit only.
git-ai-archaeology
Analyze AI config evolution in a git repo. Use when mapping AI adoption history, finding when configs were first introduced, charting commit velocity by month, or identifying maturity phases in a project's AI tooling.