cracking-technique

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions and examples for executing various command-line tools such as hashcat, john the ripper, hydra, and cewl. These commands are integral to the stated purpose of password recovery and policy auditing.
  • [INDIRECT_PROMPT_INJECTION]: The methodology involves ingesting external data from target websites (scraped via cewl) and hash files. While this establishes a potential surface for indirect prompt injection if an AI agent processes these outputs directly, the skill is focused on standard auditing workflows and lacks malicious injection patterns.
  • [DYNAMIC_EXECUTION]: A Python script executed via a one-liner command is included to filter and clean wordlist candidates. This is a localized and standard data preparation task.
  • [EXTERNAL_DOWNLOADS]: The skill references the SecLists wordlist repository and describes using tools like cewl to retrieve content from remote websites. These operations are performed within the scope of user-authorized security audits.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — cracking-technique