skills/aeondave/malskill/john/Gen Agent Trust Hub

john

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides a large suite of shell commands for the john password cracker and numerous conversion utilities (e.g., ssh2john, zip2john, office2john). These are documented for use in SKILL.md and references/formats-and-rules.md to automate cracking workflows.
  • [CREDENTIALS_UNSAFE]: The documentation explicitly references and provides commands for accessing sensitive system and credential files. This includes Linux shadow files (/etc/shadow), SSH private keys (id_rsa), and KeePass database files (.kdbx), which are targeted for hash extraction and cracking.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an indirect prompt injection surface by instructing the agent to ingest and process untrusted external files (hashes, archives, and key files) as input for CLI tools.
  • Ingestion points: External file inputs including id_rsa, archive.zip, document.pdf, database.kdbx, and /etc/shadow are identified as data sources.
  • Boundary markers: No delimiters or instructions are provided to ensure the agent ignores potentially malicious payloads embedded within the files being processed.
  • Capability inventory: The skill enables shell execution for the full John the Ripper suite, allowing for local file processing and password cracking.
  • Sanitization: There is no evidence of input validation or sanitization for file content or paths before they are passed to the conversion and cracking utilities.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — john