skills/aeondave/malskill/hashcat/Gen Agent Trust Hub

hashcat

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Provides instructions for executing Hashcat and utilities like dd and stat for hash extraction and volume analysis.\n- [PRIVILEGE_ESCALATION]: Includes commands requiring administrative or root access, such as dumping Windows SAM/SYSTEM hives and reading Linux /etc/shadow.\n- [CREDENTIALS_UNSAFE]: References sensitive system credential storage paths including /etc/shadow, /etc/passwd, and Windows SAM/SYSTEM hives.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external files (hashes, wordlists, encrypted volumes) without explicit sanitization, creating a surface for injection.\n
  • Ingestion points: File inputs to Hashcat and extraction tools in SKILL.md and references/rules-and-masks.md.\n
  • Boundary markers: None.\n
  • Capability inventory: File reading/writing (dd), system credential extraction (secretsdump.py, mimikatz), and network capture (responder).\n
  • Sanitization: None.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — hashcat