smtp-penetration-testing
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally coherent as an SMTP penetration-testing guide, and its install sources are mostly standard distro packages, but it gives an AI agent high-risk offensive security capabilities including brute force, user enumeration, spoofing, and relay abuse. The phishing-oriented example materially raises concern. This is not confirmed malware, but it is a high-risk security skill inappropriate for broad autonomous use.
Confidence: 91%Severity: 88%
Audit Metadata