SMTP Penetration Testing

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities are internally consistent, but that purpose is offensive SMTP attack execution. Install sources are mostly normal distro packages, yet the overall skill is high-risk because it equips an AI agent to enumerate users, brute-force credentials, and test relay abuse on real systems.

Confidence: 93%Severity: 91%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/davila7%2Fclaude-code-templates%2Fsmtp-penetration-testing%2F@45067d430fc57a0577a76ab71b152bd90b55b414