SMTP Penetration Testing
Warn
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to install and run various offensive security tools, including nmap, hydra, and the Metasploit Framework. It explicitly provides 'sudo apt-get install' commands, which require administrative privileges to modify the host system.
- [DATA_EXFILTRATION]: The skill facilitates the automated harvesting of sensitive information from external mail servers. This includes 'User Enumeration' to discover valid email addresses and 'Brute Force Authentication' to obtain user credentials.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes untrusted data from external SMTP servers.
- Ingestion points: Server banners, EHLO responses, and command outputs parsed during Phases 3, 4, and 6 in SKILL.md.
- Boundary markers: None. The instructions do not provide delimiters or warnings to ignore embedded instructions in server responses.
- Capability inventory: The skill has access to powerful command-line tools (nmap, hydra, msfconsole) and system-level installation privileges (sudo).
- Sanitization: None. There is no evidence of filtering or escaping logic applied to the data retrieved from external servers before the agent analyzes it.
Audit Metadata