smtp-penetration-testing
Warn
Audited by Socket on Sep 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/HIGH-RISK skill. Its capabilities match its stated purpose, and the package sources shown are mostly standard, but the purpose itself is offensive: it equips an AI agent to enumerate users, brute-force SMTP credentials, test open relays, and spoof mail. No clear credential theft or covert exfiltration is present, so this is not confirmed malware, but it is a high-risk penetration-testing skill that should be tightly restricted.
Confidence: 91%Severity: 78%
Audit Metadata