tanuki
Tactical Identity Operator for Linux & Hybrid Active Directory
Install / Use
npx skills add Mafifrizi/tanukiInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of tanuki
tanuki scores 82/100 on our quality scale, 940th of 1,112 Security skills we index.
Its SKILL.md is 25 KB long, well organised into 55 sections with 18 code examples: a thorough specification that gives an agent plenty to work with.
It has 15 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated today, so tanuki is actively maintained.
- No license is declared. By default that means all rights are reserved: you can read it, but reusing or redistributing it is not clearly permitted. Ask the author before building on it commercially.
- Its trust signals score 80/100, with 2 cautions from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands (2 minor notes below). An AI review of the same text found nothing harmful.
- noteInstalls by piping a downloaded script into a shellline 45
curl -sSL https://raw.githubusercontent.com/Mafifrizi/tanuki/main/install.sh | bash - noteInstalls by piping a downloaded script into a shellline 51
irm https://raw.githubusercontent.com/Mafifrizi/tanuki/main/install.ps1 | iex
AI review by kimi-k2.7-code on 2026-10-06. Automated pattern scan on 2026-10-06. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
tanuki compared with similar skills
All 4 of these similar skills score higher than tanuki; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| tanuki (this skill)by Mafifrizi | 82 | 15 | today | SKILL.md |
| algorithmic-artby anthropics | 100 | 177.9k | 14d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 14d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 15d ago | SKILL.md |
| ui-ux-pro-maxby nextlevelbuilder | 100 | 130.2k | 15d ago | SKILL.md |
Frequently asked questions
- How do I install tanuki?
- Run
npx skills add Mafifrizi/tanuki. The install tabs above show the steps for each supported agent. - Which AI agents does tanuki work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is tanuki safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands (2 minor notes below). An AI review of the same text found nothing harmful. It declares no license and scores 80/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is tanuki still maintained?
- The repository was last updated today, so tanuki is actively maintained.
Skill content
View source on GitHubQuick Start (1-Line Universal Install)
Tanuki is 100% plug-and-play. One command installs the unified CLI and configures AI Agent Skills for Claude Code, Cursor, and Google Antigravity:
Linux & macOS
curl -sSL https://raw.githubusercontent.com/Mafifrizi/tanuki/main/install.sh | bash
Windows (PowerShell)
irm https://raw.githubusercontent.com/Mafifrizi/tanuki/main/install.ps1 | iex
Via Pipx / Pip / Cargo
# Pipx (Isolated CLI environment)
pipx install git+https://github.com/Mafifrizi/tanuki.git
# Local repository install
pip install .
# Note for Linux (Kali, Debian, Ubuntu): If ~/.local/bin is not in your PATH:
export PATH="$HOME/.local/bin:$PATH"
# Rust binary install
cargo install --path crates/tanuki-cli
Verify your installation:
# Direct CLI binary or universal Python module
tanuki --version
python3 -m tanuki --version
tanuki doctor
tanuki ladder
tanuki triage KRB_AP_ERR_SKEW
Dual-Engine Architecture
Tanuki ships two complementary implementations:
- Rust Systems Core (
crates/tanuki-cli): The primary high-performance engine for operator workstations, CI/CD security validation pipelines, and standalone deployment. It compiles into a single static binary with#![forbid(unsafe_code)], zero external dependencies, and execution times under 2 milliseconds. - Python Fallback Engine (
scripts/): A zero-dependency script suite using only the Python standard library (struct,io,sys). It operates directly on remote target systems where dropping compiled binaries is prohibited or monitored by endpoint detection.
Both engines share an identical JSON schema and parsing specification.
Live Lab Empirical Validation
All protocol parsers, diagnostics, and CLI workflows are empirically validated across live virtualized lab environments:
- Active Directory Domain Controller: Windows Server 2022 (
DC01.lab.local, IP:192.168.56.106) - Operator Workstation: Kali Linux 2024 (
kraii@kraiiandreyy, IP:192.168.56.105)
Full-Stack End-to-End Walkthrough (Live Lab Validation)
📺 Watch Demo Video: youtu.be/wqZRYmEn0eY - Full-stack operational walkthrough across live domain infrastructure.
Visual verification of the complete 3-act operational lifecycle across live domain infrastructure:
| Act | Environment | Objectives & Validated Primitives |
| :--- | :--- | :--- |
| Act 1: Domain Controller Setup | Windows Server 2022 (DC01) | Domain discovery (nltest), SPN audit (setspn), and RFC 4120 AES-256 binary keytab export (ktpass, KVNO 9). |
| Act 2: Unprivileged Linux Operator | Kali Linux 2024 (Naga) | Passive diagnostic (tanuki doctor), RFC 4120 tree audit (tanuki keytab), zero-root config synthesis (tanuki config), native ctypes TGT acquisition (tanuki auth), ticket health pass (tanuki doctor), and protocol triage (tanuki triage). |
| Act 3: Closed-Loop Verification | Windows Server 2022 (DC01) | Domain Controller Security Event ID 4768 Audit Success for tanuki-nhi originating from client IP 192.168.56.105. |
Act 1: Domain Controller Service Setup & Keytab Provisioning (DC01)
Official RFC 4120 binary keytab export on the Domain Controller for service account LAB\tanuki-nhi with modern AES-256 (aes256-cts-hmac-sha1-96, KVNO 9):
Act 2: Unprivileged Linux Operator Session & Health Validation (Naga)
1. Pre-Flight Health Diagnostic Baseline (tanuki doctor)
Passive, zero-packet pre-flight health diagnostic executing in 0.96 ms, accurately detecting unconfigured state, missing keytabs, and inactive ticket caches:
<p align="center"> <img src="assets/lab-validation-act2-naga-doctor-unconfigured.png" alt="Act 2.1: Pre-Flight Doctor Baseline" width="850"> </p>2. RFC 4120 Keytab Ingestion & Tree Audit (tanuki keytab)
Parses binary keytab structures, extracts AES-256 principals, displays hierarchical principal trees, verifies KVNO 9, and provides automated kinit guidance:
3. Zero-DNS Kerberos Configuration Generator (tanuki config)
Generates a local Kerberos configuration file (/tmp/lab_krb5.conf) enforcing RFC 4120 § 6.1 uppercase realm conventions, zero-DNS direct KDC IP routing, and hypervisor clock-skew tolerance:
4. Unprivileged Native TGT Acquisition (tanuki auth)
Acquires a Kerberos Ticket Granting Ticket (TGT) directly from the Domain Controller using Python standard library ctypes (libkrb5.so.3) without requiring root privileges, kinit binary on PATH, or external dependencies:
5. Post-Authentication Health Diagnostic Pass (tanuki doctor)
Confirms active AES-256 Kerberos ticket cache with 9h 59m 49s remaining lifetime, executing in 1.35 ms with zero network emission:
<p align="center"> <img src="assets/lab-validation-act2-naga-doctor-pass.png" alt="Act 2.5: Post-Auth Doctor Pass with AES-256 Session" width="850"> </p>6. Kerberos Protocol Error Triage & Blue Telemetry Coupling (tanuki triage)
Couples tactical remediation commands with Blue Team detection telemetry (Auditd watch rules, Windows Event IDs 4768/4771, Sigma rules, and Falco signatures):
<p align="center"> <img src="assets/lab-validation-act2-naga-triage.png" alt="Act 2.6: Protocol Error Triage and Telemetry" width="850"> </p>Act 3: Closed-Loop Domain Controller Telemetry Verification (DC01)
Native high-efficiency log query via wevtutil on the Domain Controller proving live Event ID 4768 Audit Success for account tanuki-nhi originating from 192.168.56.105 with Ticket Encryption Type 0x12 (aes256-cts-hmac-sha1-96):
The Decision Ladder
Before proposing any triage command or query, Tanuki follows a 5-level operational ladder:
Level 5 [ Deterministic Output ] --> [Target] -> [Exact Command] -> [Artifact]
▲
Level 4 [ Targeted Vectors ] --> ADCS ESC templates, RBCD, Shadow Credentials
▲
Level 3 [ Machine Identity ] --> Leverage host keytabs and service principals (LotD)
▲
Level 2 [ OPSEC Guardrails ] --> Enforce AES-256; strictly ban RC4 and password spraying
▲
Level 1 [ Local Passive First ] --> Triage /etc/krb5.keytab & SSSD KCM before network packets
- Local Passive First: Inspect local files (
/etc/krb5.keytab,/etc/sssd/sssd.conf, KCM stores) before sending packets over the wire. - OPSEC Guardrails: Enforce AES-256 (
aes256-cts-hmac-sha1-96). Strictly forbid RC4 downgrade attacks and account spraying. - Machine Identity (Living off the Domain): Validate host keytabs and managed identities before requesting human user credentials.
- Targeted Vectors: Focus triage on specific certificate templates (ADCS), resource-based delegation, and Kerberos error codes.
- Deterministic Output: Return exact CLI invocations, target endpoints, and expected artifacts instead of general explanations.
Before & After
| Scenario | Generic Coding Agent | With Tanuki |
| :--- | :--- | :--- |
| Service LDAP Query Fails | Proposes ldapsearch -x -D "admin@corp" -W asking operator for cleartext credentials. | Inspects local keytab, acquires machine ticket via AES-256, and issues ldapsearch -Y GSSAPI with existing credentials. |
| Kerberos Error Handling | Recommends editing /etc/krb5.conf to add allow_weak_crypto = true. | Diagnoses specific Kerberos error code (KDC_ERR_ETYPE_NOSUPP or clock skew) and fixes encryption types without weakening security. |
| Ticket Cache Extraction | Searches only for /tmp/krb5cc_%{uid}, reports no tickets found when SSSD KCM is active. | Parses /var/lib/sss/secrets/secrets.ldb directly to extract active CCACHE v4 streams. |
Tooling & Usage
1. Rust Systems Core (crates/tanuki-cli)
Build the standalone binary:
cargo build --release --manifest-path crates/tanuki-cli/Cargo.toml
Run proactive pre-flight health diagnostics (<5ms, zero network packets):
tanuki doctor runs deterministic, zero-network pre-flight diagnostics across local Active Directory components in under 5 milliseconds:
- Keytab permissions and format: Audits
/etc/krb5.keytabpermissions (flags world-readable0644/0666permissions vs secure0600) and validates RFC 4120 binary header magic (0x0502). - Realm capitalization: Audits
/etc/krb5.conffor lowercase realm declarations across[libdefaults]and[realms], honoringKRB5_CONFIGenvironment variable precedence. - SSSD daemon and socket status: Validates
/var/lib/sss/pipes/kcmsocket presence and/var/run/sssd.piddaemon state. - Ticket cache lifetimes: Evaluates remaining ticket validity across MIT CCACHE v4 streams (
0x0504) and Linux Kernel Keyring (KEYRING:persistent://proc/keys). - Host client tooling: Passively audits availability of
kinit/kliston$PATHin <0.5ms and provides package recommendations for Debian/Kali (krb5-user) and RHEL (krb5-workstation).
# Terminal checklist output
tanuki doctor
# Structured JSON export for automated agent ingestion
tanuki doctor --json
# Custom target paths
tanuki doctor --keytab /custom/krb5.keytab --krb5-conf /custom/krb5.conf
Generate zero-DNS unprivileged Kerberos configuration (RFC 4120):
# Generate unprivileged configuration directly targeting KDC IP (zero root, zero DNS dependency)
tanuki config --realm CORP.LOCAL --kdc 192.168.56.106 -o ./krb5.conf
# Activate in current unprivileged shell session
export KRB5_CONFIG=$(pwd)/krb5.conf
Inspect binary keytabs (RFC 4120):
# Human-re
Truncated for display — read the full file on GitHub.
Related Skills
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
ui-ux-pro-max
130.2kUI/UX design intelligence for web, mobile, and desktop. This skill should be used when designing, building, reviewing, or fixing interfaces, including pages, components, design systems, accessibility, interaction, responsive layout, typography, color, charts, and stack-specific UI implementation.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
