hashcat
Audited by Socket on Sep 15, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS. The skill is internally consistent as a hashcat reference, but its actual purpose is to enable an AI agent to perform offensive password-cracking against sensitive authentication material. There is no clear credential exfiltration, hidden execution, or malicious install path in the skill itself, so this is not confirmed malware; however, it is a high-risk security/exploit capability for an agent and includes a loosely specified external helper binary reference.
The fragment is a Hashcat and credential-auditing reference containing potentially offensive commands for password cracking, credential extraction, authentication capture, and wireless capture. It contains no apparent malware or obfuscated payload and is not executable package code. Use should be restricted to authorized security testing and incident-response activities.