cracking-technique

Fail

Audited by Socket on Sep 5, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The static findings are mostly documentation false positives, and I see no confirmed malware or hidden exfiltration. However, the skill’s true purpose is to equip an AI agent with password-cracking and related offensive methodology, including escalation toward online authentication attacks via linked Hydra tooling; that makes it a high-risk offensive-security skill even when framed as authorized auditing.

Confidence: 91%Severity: 78%
MalwareHIGH
references/progressive-cracking.md

High-confidence identification of an offensive, iterative password-cracking workflow. The fragment provides direct, actionable instructions to recover plaintext credentials from password hashes using Hashcat, including use of OSINT/leak-derived wordlists, potfile-based result disclosure, and a closed-loop refinement process that generates and reuses derived candidate material. While it contains no malware code or network exfiltration within the snippet, its purpose and operational behavior strongly enable unauthorized access/credential theft.

Confidence: 88%Severity: 95%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:44 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fcracking-technique%2F@2c1a64149103c4705bd8b709145651d7718d278e5cf9db53aedad412ddac9bc3
Security Audit — socket — cracking-technique