skills/aeondave/malskill/hydra/Gen Agent Trust Hub

hydra

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous command-line examples for executing the hydra utility. It details various flags for credential testing, thread management, and proxy usage across protocols like SSH, SMB, and HTTP.
  • [INDIRECT_PROMPT_INJECTION]: As the skill instructs the agent to process responses from external network targets (e.g., matching 'failure strings' in HTTP responses), it creates an attack surface where a malicious target could return content designed to influence the agent's behavior.
  • Ingestion points: Tool output from hydra stdout and result files specified via the -o flag in SKILL.md.
  • Boundary markers: None provided in the command templates or instructions.
  • Capability inventory: Execution of the hydra binary, which performs network operations across 50+ protocols and local file writing for result logs.
  • Sanitization: The skill does not provide methods for sanitizing target responses before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — hydra