hydra

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent as a Hydra reference, but its purpose is explicitly offensive: it equips an AI agent to conduct brute-force and password-spraying attacks, including evasion tactics. There is no clear malicious exfiltration path or deceptive installer in the text, so this is better classified as high-risk offensive security enablement rather than confirmed malware.

Confidence: 92%Severity: 87%
SecurityMEDIUM
references/protocols.md

This is attack-oriented Hydra usage documentation for automated credential guessing against network services. It contains no executable malware or hidden payload, but using these commands without explicit authorization can lead to credential compromise, account lockouts, alerts, and service disruption. The primary concern is misuse of the documented tooling rather than supply-chain malware in the provided text.

Confidence: 99%Severity: 78%
Audit Metadata
Analyzed At
Sep 15, 2026, 09:58 AM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fhydra%2F@5f0258cd886d04ee793e751b734641f03e659f764062c4fd3c590c980a774ff1
Security Audit — socket — hydra