wireless-evil-twin
Warn
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONCREDENTIALS_UNSAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides specific shell command instructions for executing wireless attack and cracking tools, including
eaphammer --cert-wizard,eaphammer -i wlan0 --essid <SSID> --creds, andhashcat -m 5500 netntlm.txt wordlist. - [CREDENTIALS_UNSAFE]: The primary objective of the instructions is the harvesting of authentication credentials, specifically PEAP-MSCHAPv2 challenge/response pairs and credentials typed into a captive portal.
- [DATA_EXFILTRATION]: The skill describes a workflow for capturing sensitive user data (usernames and passwords) from external devices via a rogue RADIUS server or portal and storing them for offline analysis.
- [INDIRECT_PROMPT_INJECTION]: The skill describes a workflow involving a captive-portal variant which constitutes a surface for processing untrusted external data.
- Ingestion points: Data entered by users into a cloned portal page (SKILL.md, Step 5).
- Boundary markers: Mentions adherence to
social-eng-methodologyandtradecraft-scope-roeas external guardrails. - Capability inventory: Capability to log credentials, control wireless interfaces, and execute offline password cracking (
hashcat). - Sanitization: No specific instructions for sanitizing or validating the untrusted input captured from the captive portal are provided.
Audit Metadata