smtp-penetration-testing
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill contains instructions for installing several security tools using
sudo apt-get install, includingnmap,netcat,hydra, andsmtp-user-enum. These commands are standard for setting up a security assessment environment. - [COMMAND_EXECUTION]: The workflow involves various network scanning and enumeration commands aimed at identifying SMTP server configurations, banners, and supported extensions.
- [COMMAND_EXECUTION]: Detailed instructions are provided for performing active security testing, such as user enumeration (via VRFY/EXPN/RCPT), open relay testing, and credential brute-forcing using Hydra and Metasploit.
- [COMMAND_EXECUTION]: Includes network-based verification steps using
openssl s_clientanddigto analyze TLS configurations and email authentication records (SPF, DKIM, DMARC).
Audit Metadata