hydra
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous command-line examples for executing the
hydrautility. It details various flags for credential testing, thread management, and proxy usage across protocols like SSH, SMB, and HTTP. - [INDIRECT_PROMPT_INJECTION]: As the skill instructs the agent to process responses from external network targets (e.g., matching 'failure strings' in HTTP responses), it creates an attack surface where a malicious target could return content designed to influence the agent's behavior.
- Ingestion points: Tool output from
hydrastdout and result files specified via the-oflag inSKILL.md. - Boundary markers: None provided in the command templates or instructions.
- Capability inventory: Execution of the
hydrabinary, which performs network operations across 50+ protocols and local file writing for result logs. - Sanitization: The skill does not provide methods for sanitizing target responses before they are processed by the agent.
Audit Metadata