SMTP Penetration Testing

Fail

Audited by Snyk on Jul 28, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The document contains explicit, actionable offensive instructions (user enumeration, brute-force authentication, open-relay exploitation, header injection/spoofing and tooling) that enable deliberate malicious activity such as harvesting accounts and preparing phishing or spam campaigns.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). SKILL.md instructs runtime probing of a target SMTP server (e.g., banner grabbing and relay/user testing via nmap/telnet/nc/smtp-user-enum), whose responses (outsider-authored remote service text) are then parsed and could be included in the agent’s LLM context as results/output.

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill explicitly instructs installing system packages using sudo (e.g., "sudo apt-get install nmap/netcat/hydra/smtp-user-enum"), which requires elevated privileges and modifies the host system state, so it should be flagged.

Issues (3)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 28, 2026, 05:46 AM
Issues
3
Security Audit — snyk — SMTP Penetration Testing