zimbra-attack

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its behavior is internally consistent with its stated purpose, but that purpose is offensive security against third-party Zimbra systems. No strong signs of malware or hidden exfiltration, yet the exploit-focused probes, SSRF testing, and autonomous attack workflow make it unsafe for general agent use.

Confidence: 93%Severity: 91%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fzimbra-attack%2F@88362e2925d8dc6c0b8929f8384c95a674a5cd220424dd711971da4a1da6ecac
Security Audit — socket — zimbra-attack