Agent skill

Auditing Tls Certificate Transparency Logs

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains.

Apache-2.0Auto-check passedDevOps & Cloud

Install Auditing Tls Certificate Transparency Logs

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill auditing-tls-certificate-transparency-logs -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills auditing-tls-certificate-transparency-logs --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/auditing-tls-certificate-transparency-logs .claude/skills/auditing-tls-certificate-transparency-logs && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
auditing-tls-certificate-transparency-logs
GitHub stars
34k
Token cost
~4k tokens
SKILL.md length
1,808 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains.

  • Works in 5 steps: Domain Inventory and Baseline → Continuous CT Log Monitoring → Subdomain Discovery via CT Data → …
  • Tasks that involve Cloud networking
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; reaches crt.sh

What it does

Auditing Tls Certificate Transparency Logs is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains. Uses the crt.sh API and direct CT log querying based on RFC 6962 to build continuous monitoring pipelines that catch rogue certificates, track CA behavior, and map the external attack surface. Activates for requests involving certificate transparency monitoring, CT log auditing, subdomain discovery via certificates, or certificate…

Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in DevOps & Cloud, covering Cloud networking, Threat modeling and Cryptography. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Cloud networking
  • Tasks that involve Threat modeling
  • Tasks that involve Cryptography

Example prompts

  • “Use the auditing-tls-certificate-transparency-logs skill to monitor Certificate Transparency (CT) logs to detect unauthorized certificate issuance…”
  • “/auditing-tls-certificate-transparency-logs”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Domain Inventory and Baseline
  2. Continuous CT Log Monitoring
  3. Subdomain Discovery via CT Data
  4. Certificate Issuance Alerting
  5. CT Log Integrity Verification and Reporting

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • crt.sh

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Auditing Tls Certificate Transparency Logs loads about 4k tokens when it runs, and up to ~5.6k if it reads all its reference files. Until then it costs about 145 tokens; SKILL.md has 1,808 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~145
When it runs · the whole SKILL.md, loaded when a task matches
~4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 1,808 words, ~3,950 tokens.

Download SKILL.mdSave it as .claude/skills/auditing-tls-certificate-transparency-logs/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
auditing-tls-certificate-transparency-logs
description
Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains. Uses the crt.sh API and direct CT log querying based on RFC 6962 to build continuous monitoring pipelines that catch rogue certificates, track CA behavior, and map the external attack surface. Activates for requests involving certificate transparency monitoring, CT log auditing, subdomain discovery via certificates, or certificate issuance alerting.
domain
cybersecurity
subdomain
threat-intelligence
tags
certificate-transparency, CT-logs, crt-sh, subdomain-discovery, TLS-monitoring, RFC-6962
version
1.0.0
author
mukul975
license
Apache-2.0
nist_csf
ID.RA-01, ID.RA-05, DE.CM-01, DE.AE-02
mitre_attack
T1596.003, T1583.001, T1587.003, T1593, T1566.002

Auditing TLS Certificate Transparency Logs

When to Use

  • Monitoring owned domains for unauthorized or unexpected certificate issuance by unknown Certificate Authorities
  • Discovering subdomains and hidden services through certificates logged in public CT logs
  • Detecting phishing infrastructure that uses look-alike domain certificates (typosquatting, homograph attacks)
  • Auditing Certificate Authority compliance by verifying all issued certificates appear in CT logs as required by browser policies
  • Building continuous certificate monitoring into a security operations pipeline with alerting for new issuances

Do not use for attacking or disrupting Certificate Authorities, for scraping CT logs in violation of rate limits or terms of service, or as the sole method of subdomain enumeration without corroborating results through DNS verification.

Prerequisites

  • Python 3.10+ with requests, cryptography, and pyOpenSSL libraries installed
  • Network access to crt.sh (HTTPS) and public CT log servers
  • A list of domains to monitor (owned domains, brand variations, typosquat candidates)
  • SMTP credentials or webhook URL for alerting on new certificate discoveries
  • Basic understanding of X.509 certificate structure and TLS certificate chain validation

Workflow

Step 1: Domain Inventory and Baseline

Build the initial certificate inventory for monitored domains:

  • Define monitoring scope: List all owned root domains, registered brand names, and known subsidiaries. Include wildcard patterns (%.example.com) for comprehensive subdomain coverage.
  • Query crt.sh for historical certificates: Use the crt.sh JSON API to retrieve all known certificates for each domain. The API endpoint https://crt.sh/?q=%.example.com&output=json returns certificates matching the wildcard pattern with fields including issuer_ca_id, issuer_name, common_name, name_value, not_before, not_after, and serial_number.
  • Build baseline database: Store the initial certificate set in a local SQLite database with columns for certificate ID, domain, issuer, validity dates, SANs (Subject Alternative Names), and first-seen timestamp. This baseline prevents alerting on already-known certificates.
  • Identify authorized CAs: From the baseline, extract the set of Certificate Authorities that have legitimately issued certificates for your domains. Any future issuance from a CA not in this set triggers a high-priority alert.
  • Map subdomains: Extract all unique subdomains from the name_value field across all certificates to build an initial subdomain inventory.
Step 2: Continuous CT Log Monitoring

Set up ongoing monitoring for new certificate issuances:

  • Poll crt.sh periodically: Query the crt.sh API at regular intervals (every 15-60 minutes) for new certificates. Use the exclude=expired parameter to focus on currently valid certificates. Compare results against the baseline database to identify new entries.
  • Parse certificate details: For each new certificate, extract the full SAN list, issuer chain, validity period, key type and size, CT log SCT (Signed Certificate Timestamp) details, and certificate fingerprint (SHA-256).
  • Detect precertificates: CT logs include precertificates (poisoned certificates submitted before final issuance). Track these as early warnings since they indicate a certificate is about to be issued but may not yet be active.
  • Monitor CT log Signed Tree Heads (STH): For advanced monitoring, query CT log servers directly to fetch the latest STH and verify consistency proofs between consecutive tree heads. An inconsistency indicates log misbehavior (split-view attack).
  • Rate limiting awareness: Respect crt.sh rate limits by spacing queries and caching responses. Implement exponential backoff on HTTP 429 responses. For high-volume monitoring, consider querying the crt.sh PostgreSQL interface directly at crt.sh:5432.
  • Atom/RSS feed alternative: Subscribe to crt.sh's Atom feed for lighter-weight monitoring: https://crt.sh/atom?q=%25.example.com provides real-time notification of new log entries.
Step 3: Subdomain Discovery via CT Data

Extract and validate subdomains found in certificate transparency data:

  • Wildcard expansion: Certificates with wildcard SANs (*.dev.example.com) reveal the existence of subdomains that may not be in DNS zone files. Record the parent domain as a target for further enumeration.
  • Historical certificate mining: Query crt.sh without the exclude=expired parameter to find subdomains from expired certificates that may still resolve in DNS. These represent historical infrastructure that could be vulnerable to subdomain takeover.
  • DNS validation: For each discovered subdomain, perform DNS resolution (A, AAAA, CNAME records) to determine if the subdomain is currently active. Cross-reference with known IP ranges to identify shadow IT or unauthorized services.
  • Typosquat detection: Generate permutations of the monitored domain (bitsquatting, homograph, insertion, omission, transposition, keyboard-adjacent replacement) and query CT logs for certificates issued to these variations. Certificates for typosquat domains strongly indicate phishing infrastructure.
  • Deduplication and enrichment: Normalize discovered subdomains (lowercase, remove trailing dots), deduplicate, and enrich with WHOIS data, IP geolocation, and HTTP response headers to prioritize investigation.
Step 4: Certificate Issuance Alerting

Configure alerting rules for security-relevant certificate events:

  • Unauthorized CA alert: Trigger when a certificate is issued by a CA not in the authorized CA list. This is the highest-priority alert as it may indicate domain hijacking, BGP hijacking for domain validation, or a compromised CA.
  • New subdomain alert: Trigger when a certificate contains a SAN with a previously unseen subdomain. This catches shadow IT deployments and unauthorized services.
  • Wildcard certificate alert: Trigger on any new wildcard certificate issuance, as wildcard certificates have broader impact if compromised and their issuance should be tightly controlled.
  • Short-lived certificate anomaly: Alert when certificates have unusually short validity periods (under 24 hours) that deviate from the organization's normal certificate lifecycle, as this may indicate Let's Encrypt abuse or automated phishing infrastructure.
  • Expiration warning: Alert when certificates for critical services approach expiration (30, 14, 7 days) based on the not_after field from CT log data.
  • Alert delivery: Send alerts via email (SMTP), Slack webhook, PagerDuty, or write to a SIEM-compatible JSON log format for integration with existing security monitoring.
Step 5: CT Log Integrity Verification and Reporting

Verify log integrity and produce compliance evidence:

  • Signed Tree Head (STH) monitoring: Fetch the latest STH from each monitored CT log via the get-sth API endpoint. The STH contains the tree size and a signed timestamp. Verify the signature using the log's public key.
  • Consistency proof verification: Between consecutive STH fetches, request a consistency proof via get-sth-consistency to verify the log remains append-only and no entries have been modified or removed.
  • Certificate inventory report: Produce a complete inventory of all certificates issued for monitored domains, grouped by issuer, with validity status and key strength metrics.
  • CA diversity analysis: Report on how many different CAs issue certificates for the organization, identifying consolidation opportunities and single-points-of-failure.
  • Compliance evidence: For organizations subject to PCI-DSS, SOC 2, or similar frameworks, CT monitoring logs provide evidence of certificate lifecycle management and unauthorized issuance detection capabilities.
Show full SKILL.md (782 more words)Show less

Key Concepts

TermDefinition
Certificate Transparency (CT)An open framework (RFC 6962) requiring Certificate Authorities to log all issued certificates in publicly auditable append-only logs, enabling domain owners to detect unauthorized issuance
Signed Certificate Timestamp (SCT)A promise from a CT log that a certificate will be included within the Maximum Merge Delay (typically 24 hours); browsers require SCTs from multiple logs before trusting a certificate
Merkle TreeThe cryptographic data structure used by CT logs where leaf nodes are certificate hashes and parent nodes are hashes of their children, enabling efficient consistency and inclusion proofs
PrecertificateA certificate submitted to CT logs before final issuance, containing a poison extension (OID 1.3.6.1.4.1.11129.2.4.3) that prevents it from being used for TLS but reserves its place in the log
crt.shA free web service operated by Sectigo that aggregates certificates from all major CT logs into a searchable PostgreSQL database, providing both web and API access
Subdomain TakeoverA vulnerability where a subdomain's DNS record points to a decommissioned service (cloud provider, CDN) that an attacker can reclaim, made discoverable through expired CT certificates
Maximum Merge Delay (MMD)The maximum time (typically 24 hours) a CT log has to incorporate a submitted certificate into its Merkle tree after returning an SCT
CAA RecordDNS Certification Authority Authorization record that specifies which CAs are permitted to issue certificates for a domain; CT monitoring detects violations of CAA policy

Tools & Systems

  • crt.sh: Primary CT log aggregator providing JSON API access at https://crt.sh/?q=<query>&output=json with support for wildcard queries, identity filtering, and certificate detail retrieval
  • ct-woodpecker: Open-source CT log monitoring tool from Let's Encrypt that integrates with Prometheus and Grafana for operational monitoring of log health and consistency
  • certspotter: SSLMate's CT log monitor that watches for newly issued certificates and sends notifications; available as hosted service or self-hosted tool
  • Google Argon / Xenon / Icarus: Google-operated CT logs that are among the most widely used, queryable via the RFC 6962 API at their respective log URLs
  • OpenSSL: Command-line tool for parsing certificate details, verifying chains, and extracting SAN lists from certificates retrieved through CT monitoring

Common Scenarios

Scenario: Detecting Unauthorized Certificate Issuance for a Financial Services Company

Context: A bank monitors its primary domain (bank.example.com) and discovers via CT logs that a certificate has been issued by a CA they have never used, covering secure-login.bank.example.com -- a subdomain that does not exist in their DNS.

Approach:

  1. CT monitoring agent detects a new certificate from "FreeSSL CA" for secure-login.bank.example.com in crt.sh results, which is not in the authorized CA list (DigiCert, Sectigo)
  2. Alert fires as unauthorized CA + new subdomain, escalating to the security team within 15 minutes of CT log entry
  3. Investigate the certificate: extract the public key, check if the domain validated via HTTP-01 or DNS-01 challenge, query WHOIS for the issuing organization
  4. DNS lookup for secure-login.bank.example.com reveals it resolves to an IP address in a hosting provider not used by the bank -- confirming this is attacker infrastructure
  5. Initiate incident response: request certificate revocation from FreeSSL CA, file a domain abuse report, add the IP to blocklists, and notify the anti-phishing team
  6. Implement CAA DNS records (bank.example.com. CAA 0 issue "digicert.com") to prevent unauthorized CAs from issuing future certificates

Pitfalls:

  • Not monitoring wildcard patterns (%.bank.example.com) and missing certificates for subdomains
  • Ignoring precertificates that appear in CT logs before the actual certificate is issued, losing the early warning advantage
  • Failing to verify that CAA records are properly configured on all domains after an incident
  • Over-alerting on legitimate certificate renewals because the baseline database was not updated after authorized changes
Scenario: Attack Surface Mapping Through CT Log Subdomain Discovery

Context: A penetration tester uses CT logs as the first phase of external reconnaissance to map the target organization's internet-facing services before active scanning.

Approach:

  1. Query crt.sh for %.target.com and all known subsidiary domains, collecting 2,400 unique certificates spanning 8 years
  2. Extract 347 unique subdomains from SAN fields across all certificates, including expired ones
  3. DNS-resolve all 347 subdomains, finding 189 currently active with A/AAAA records
  4. Identify 12 subdomains pointing to decommissioned cloud services (CNAME to S3 buckets, Azure endpoints) that are candidates for subdomain takeover
  5. Discover staging-api.target.com and dev-portal.target.com which are not in the target's documented scope but are reachable and running older software versions
  6. Present findings to the target organization showing the gap between their known asset inventory and the CT-derived attack surface

Pitfalls:

  • Assuming all CT-discovered subdomains are in scope without confirming with the asset owner
  • Not checking for wildcard DNS responses that make it appear subdomains exist when they resolve to a catch-all
  • Relying solely on CT data without cross-referencing with passive DNS databases for comprehensive coverage

Output Format

## CT Log Monitoring Report

**Domain**: example.com
**Monitoring Period**: 2026-03-01 to 2026-03-19
**Total Certificates Tracked**: 142
**New Certificates Detected**: 7
**Alerts Generated**: 2

### Alert: Unauthorized CA Issuance
- **Severity**: Critical
- **Certificate CN**: secure-login.example.com
- **SANs**: secure-login.example.com, www.secure-login.example.com
- **Issuer**: Unknown Free CA (NOT in authorized CA list)
- **Serial**: 04:A3:B7:2F:...:9E
- **Not Before**: 2026-03-18T00:00:00Z
- **Not After**: 2026-06-16T00:00:00Z
- **CT Log**: Google Argon 2026
- **SCT Timestamp**: 2026-03-17T22:15:33Z
- **Action Required**: Investigate immediately, request revocation

### Subdomain Discovery Summary
- **Total Unique Subdomains**: 89
- **New Subdomains This Period**: 3
  - api-v3.example.com (DigiCert, valid)
  - staging-new.example.com (Let's Encrypt, valid)
  - old-portal.example.com (expired 2025-12-01, CNAME to Azure -- takeover risk)

### Typosquatting Alerts
| Domain | Certificate Count | Issuer | Action Required |
|--------|-------------------|--------|-----------------|
| exarnple.com | 2 | Let's Encrypt | Investigate phishing |
| examp1e.com | 1 | ZeroSSL | Investigate phishing |

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/auditing-tls-certificate-transparency-logs of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Auditing Tls Certificate Transparency Logs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Auditing Tls Certificate Transparency Logs compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Auditing Tls Certificate Transparency Logs this skillmukul975/Anthropic-Cybersecurity-Skills34k—~4kAutomated safety check: PassApache-2.0
Ssl Tls Managementsickn33/agentic-awesome-skills47k2 repos~2.8kAutomated safety check: PassMIT
Implementing Tlsancoleman/ai-design-components525—~3.6kAutomated safety check: NotesMIT
External Enumerationforefy/.context152—~3.1kAutomated safety check: PassMIT
Detecting Ssl Cert Issuesjeremylongshore/tons-of-skills-marketplace2.8k—~1.7kAutomated safety check: PassMIT
Migrate Dotnet9 To Dotnet10dotnet/skills5.6k2 repos~4.8kAutomated safety check: PassMIT

Similar skills

  • Ssl Tls Management

    sickn33/agentic-awesome-skills

    Manage SSL/TLS certificates with Let's Encrypt and internal PKI.

    47k GitHub starsUsed in 2 repos~2.8k tokens
    DevOps & CloudAuto-check passed
  • Implementing Tls

    ancoleman/ai-design-components

    Configure TLS certificates and encryption for secure communications.

    525 GitHub stars~3.6k tokensUpdated 10 mo ago
    SecurityAuto-check: notes
  • External Enumeration

    forefy/.context

    Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs.

    152 GitHub stars~3.1k tokensUpdated 6 days ago
    SecurityAuto-check passed
  • Detecting Ssl Cert Issues

    jeremylongshore/tons-of-skills-marketplace

    Audit a target's TLS certificate beyond protocol/expiry — chain ordering, OCSP stapling, revocation status, Certificate Transparency presence, key-usage flags, and over-broad wildcards.

    2.8k GitHub stars~1.7k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Official

    Migrate a .NET 9 project or solution to .NET 10 and resolve all breaking changes.

    5.6k GitHub starsUsed in 2 repos~4.8k tokens
    DevOps & CloudAuto-check passed
  • Senior Security

    davila7/claude-code-templates

    Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing.

    33k GitHub starsUsed in 2 repos~1.1k tokens
    SecurityAuto-check: notes

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Auditing Tls Certificate Transparency Logs

What does Auditing Tls Certificate Transparency Logs do?

Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains. Auditing Tls Certificate Transparency Logs is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains.

When should I use Auditing Tls Certificate Transparency Logs?

Auditing Tls Certificate Transparency Logs fits situations like: tasks that involve Cloud networking; tasks that involve Threat modeling; tasks that involve Cryptography.

How do I install Auditing Tls Certificate Transparency Logs in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill auditing-tls-certificate-transparency-logs -a claude-code`. Or copy the skill folder (skills/auditing-tls-certificate-transparency-logs in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/auditing-tls-certificate-transparency-logs in your project. Claude Code loads it when a task matches its description.

How do I install Auditing Tls Certificate Transparency Logs in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill auditing-tls-certificate-transparency-logs -a codex`. Or copy the skill folder (skills/auditing-tls-certificate-transparency-logs in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/auditing-tls-certificate-transparency-logs in your project. Codex loads it when a task matches its description.

Can I use Auditing Tls Certificate Transparency Logs in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill auditing-tls-certificate-transparency-logs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auditing-tls-certificate-transparency-logs, .gemini/skills/auditing-tls-certificate-transparency-logs, .github/skills/auditing-tls-certificate-transparency-logs and .opencode/skills/auditing-tls-certificate-transparency-logs in your project.

What does Auditing Tls Certificate Transparency Logs need to run?

Going by SKILL.md and its folder, Auditing Tls Certificate Transparency Logs needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Auditing Tls Certificate Transparency Logs access the network?

SKILL.md names 1 domain. In commands or code: crt.sh; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Auditing Tls Certificate Transparency Logs safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Auditing Tls Certificate Transparency Logs use?

Auditing Tls Certificate Transparency Logs is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Auditing Tls Certificate Transparency Logs use?

About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.

What are the alternatives to Auditing Tls Certificate Transparency Logs?

Skills that share tags, products or a category with Auditing Tls Certificate Transparency Logs: Ssl Tls Management (sickn33/agentic-awesome-skills, 47k stars), Implementing Tls (ancoleman/ai-design-components, 525 stars), External Enumeration (forefy/.context, 152 stars) and Detecting Ssl Cert Issues (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Auditing Tls Certificate Transparency Logs?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.