SMTP Penetration Testing

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This README-style skill is a comprehensive, explicit active-testing guide for SMTP servers. It is not itself malware and contains no obfuscated or covert exfiltration logic, but it contains detailed, dual-use offensive techniques (user enumeration, relay exploitation, brute forcing) that pose significant operational risk if used without authorization. Recommend restricting distribution, adding mandatory authorization verification and safe-mode defaults (no external recipients, rate limits), guidance for secure storage/handling of captured credentials, and verifying provenance of recommended third-party tooling before installation.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:10 PM
Package URL
pkg:socket/skills-sh/davila7%2Fclaude-code-templates%2Fsmtp-penetration-testing%2F@45067d430fc57a0577a76ab71b152bd90b55b414