cred-spray
Warn
Audited by Gen Agent Trust Hub on May 9, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill provides instructions for harvesting sensitive credentials, including SSH private keys (~/.ssh/id_rsa), NTLM hashes from system memory (LSASS) and SAM databases, and cleartext secrets stored in configuration (.env) or history files (.bash_history).
- [COMMAND_EXECUTION]: The documentation includes command-line templates for tools such as crackmapexec and xfreerdp to automate the testing of credentials across multiple network targets using protocols like SMB, RDP, WMI, and SSH.
- [PROMPT_INJECTION]: The skill outlines a workflow for indirect prompt injection where harvested credentials and user lists are used directly in shell commands. Ingestion points: Collected credential files and system artifacts (SKILL.md). Boundary markers: Absent. No delimiters are suggested to isolate untrusted harvested data. Capability inventory: Subprocess execution via cme, xfreerdp, and nuclei. Sanitization: Absent. The instructions do not include steps to validate or escape harvested strings before use in commands.
Audit Metadata