password-spray-methodology
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill contains various shell commands and scripts intended for network probing and executing password sprays against targets. Evidence includes loops using
curlfor lockout detection and specific command-line examples for tools likekerbruteandnetexecacross different protocols. The verification section also includes commands to check for tool availability on the local system. - [EXTERNAL_DOWNLOADS]: The skill references a variety of external security tools and packages necessary for the methodology. This includes Python packages like
o365sprayand third-party binaries such askerbrute,crackmapexec, andusername-anarchy. The verification block explicitly checks for these dependencies.
Audit Metadata