SMTP Penetration Testing

Warn

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to install and run various offensive security tools, including nmap, hydra, and the Metasploit Framework. It explicitly provides 'sudo apt-get install' commands, which require administrative privileges to modify the host system.
  • [DATA_EXFILTRATION]: The skill facilitates the automated harvesting of sensitive information from external mail servers. This includes 'User Enumeration' to discover valid email addresses and 'Brute Force Authentication' to obtain user credentials.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes untrusted data from external SMTP servers.
  • Ingestion points: Server banners, EHLO responses, and command outputs parsed during Phases 3, 4, and 6 in SKILL.md.
  • Boundary markers: None. The instructions do not provide delimiters or warnings to ignore embedded instructions in server responses.
  • Capability inventory: The skill has access to powerful command-line tools (nmap, hydra, msfconsole) and system-level installation privileges (sudo).
  • Sanitization: None. There is no evidence of filtering or escaping logic applied to the data retrieved from external servers before the agent analyzes it.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 28, 2026, 05:45 AM
Security Audit — agent-trust-hub — SMTP Penetration Testing