john
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides a large suite of shell commands for the
johnpassword cracker and numerous conversion utilities (e.g.,ssh2john,zip2john,office2john). These are documented for use inSKILL.mdandreferences/formats-and-rules.mdto automate cracking workflows. - [CREDENTIALS_UNSAFE]: The documentation explicitly references and provides commands for accessing sensitive system and credential files. This includes Linux shadow files (
/etc/shadow), SSH private keys (id_rsa), and KeePass database files (.kdbx), which are targeted for hash extraction and cracking. - [INDIRECT_PROMPT_INJECTION]: The skill establishes an indirect prompt injection surface by instructing the agent to ingest and process untrusted external files (hashes, archives, and key files) as input for CLI tools.
- Ingestion points: External file inputs including
id_rsa,archive.zip,document.pdf,database.kdbx, and/etc/shadoware identified as data sources. - Boundary markers: No delimiters or instructions are provided to ensure the agent ignores potentially malicious payloads embedded within the files being processed.
- Capability inventory: The skill enables shell execution for the full John the Ripper suite, allowing for local file processing and password cracking.
- Sanitization: There is no evidence of input validation or sanitization for file content or paths before they are passed to the conversion and cracking utilities.
Audit Metadata