zimbra-attack
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
curland standard shell scripting to perform network requests and parse responses. This is the intended primary purpose of the skill for performing security reconnaissance on Zimbra targets. - [SAFE]: While the skill performs offensive security actions (user enumeration, CVE scanning, SSRF probing), these behaviors are explicitly described in the documentation and match the user's intent when using a 'recon' and 'attack' themed skill. The script does not exfiltrate sensitive local data, does not include obfuscated code, and does not maintain persistence on the agent's system.
Audit Metadata