imap-pentesting
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill methodology involves executing standard security tools such as
nmap,hydra,medusa,ncrack, andmsfconsolefor auditing IMAP services. These tools are used within their intended scope for security testing. - [EXTERNAL_DOWNLOADS]: Includes instructions for the agent to install the 'evolution' mail client through the system package manager to assist in visualizing email data.
- [PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection as it is designed to retrieve and process content from external mail servers:
- Ingestion points: Untrusted content enters the context via
curlandimaplibfetches of email bodies and headers inSKILL.mdandreferences/imap-techniques.md. - Boundary markers: Absent. The instructions do not define delimiters to separate fetched email data from agent instructions.
- Capability inventory: The skill context includes access to powerful CLI tools (
nc,openssl,nmap,hydra,curl) and package installation capabilities as described inSKILL.md. - Sanitization: Absent. There is no logic provided to sanitize or validate the content of the emails before they are analyzed by the agent.
Audit Metadata