hydra
Audited by Socket on Sep 15, 2026
2 alerts found:
Securityx2SUSPICIOUS. The skill is internally coherent as a Hydra reference, but its purpose is explicitly offensive: it equips an AI agent to conduct brute-force and password-spraying attacks, including evasion tactics. There is no clear malicious exfiltration path or deceptive installer in the text, so this is better classified as high-risk offensive security enablement rather than confirmed malware.
This is attack-oriented Hydra usage documentation for automated credential guessing against network services. It contains no executable malware or hidden payload, but using these commands without explicit authorization can lead to credential compromise, account lockouts, alerts, and service disruption. The primary concern is misuse of the documented tooling rather than supply-chain malware in the provided text.