wireless-evil-twin

Warn

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONCREDENTIALS_UNSAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides specific shell command instructions for executing wireless attack and cracking tools, including eaphammer --cert-wizard, eaphammer -i wlan0 --essid <SSID> --creds, and hashcat -m 5500 netntlm.txt wordlist.
  • [CREDENTIALS_UNSAFE]: The primary objective of the instructions is the harvesting of authentication credentials, specifically PEAP-MSCHAPv2 challenge/response pairs and credentials typed into a captive portal.
  • [DATA_EXFILTRATION]: The skill describes a workflow for capturing sensitive user data (usernames and passwords) from external devices via a rogue RADIUS server or portal and storing them for offline analysis.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a workflow involving a captive-portal variant which constitutes a surface for processing untrusted external data.
  • Ingestion points: Data entered by users into a cloned portal page (SKILL.md, Step 5).
  • Boundary markers: Mentions adherence to social-eng-methodology and tradecraft-scope-roe as external guardrails.
  • Capability inventory: Capability to log credentials, control wireless interfaces, and execute offline password cracking (hashcat).
  • Sanitization: No specific instructions for sanitizing or validating the untrusted input captured from the captive portal are provided.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 20, 2026, 11:02 PM
Security Audit — agent-trust-hub — wireless-evil-twin