cracking-technique
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions and examples for executing various command-line tools such as hashcat, john the ripper, hydra, and cewl. These commands are integral to the stated purpose of password recovery and policy auditing.
- [INDIRECT_PROMPT_INJECTION]: The methodology involves ingesting external data from target websites (scraped via cewl) and hash files. While this establishes a potential surface for indirect prompt injection if an AI agent processes these outputs directly, the skill is focused on standard auditing workflows and lacks malicious injection patterns.
- [DYNAMIC_EXECUTION]: A Python script executed via a one-liner command is included to filter and clean wordlist candidates. This is a localized and standard data preparation task.
- [EXTERNAL_DOWNLOADS]: The skill references the SecLists wordlist repository and describes using tools like cewl to retrieve content from remote websites. These operations are performed within the scope of user-authorized security audits.
Audit Metadata