hashcat
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Provides instructions for executing Hashcat and utilities like
ddandstatfor hash extraction and volume analysis.\n- [PRIVILEGE_ESCALATION]: Includes commands requiring administrative or root access, such as dumping Windows SAM/SYSTEM hives and reading Linux/etc/shadow.\n- [CREDENTIALS_UNSAFE]: References sensitive system credential storage paths including/etc/shadow,/etc/passwd, and Windows SAM/SYSTEM hives.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external files (hashes, wordlists, encrypted volumes) without explicit sanitization, creating a surface for injection.\n - Ingestion points: File inputs to Hashcat and extraction tools in
SKILL.mdandreferences/rules-and-masks.md.\n - Boundary markers: None.\n
- Capability inventory: File reading/writing (
dd), system credential extraction (secretsdump.py,mimikatz), and network capture (responder).\n - Sanitization: None.
Audit Metadata