password-spray-methodology

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains various shell commands and scripts intended for network probing and executing password sprays against targets. Evidence includes loops using curl for lockout detection and specific command-line examples for tools like kerbrute and netexec across different protocols. The verification section also includes commands to check for tool availability on the local system.
  • [EXTERNAL_DOWNLOADS]: The skill references a variety of external security tools and packages necessary for the methodology. This includes Python packages like o365spray and third-party binaries such as kerbrute, crackmapexec, and username-anarchy. The verification block explicitly checks for these dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:47 PM
Security Audit — agent-trust-hub — password-spray-methodology