smtp-penetration-testing

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its capabilities match its stated purpose, and the package sources shown are mostly standard, but the purpose itself is offensive: it equips an AI agent to enumerate users, brute-force SMTP credentials, test open relays, and spoof mail. No clear credential theft or covert exfiltration is present, so this is not confirmed malware, but it is a high-risk penetration-testing skill that should be tightly restricted.

Confidence: 91%Severity: 78%
Audit Metadata
Analyzed At
Sep 18, 2026, 01:25 PM
Package URL
pkg:socket/skills-sh/zebbern%2Fclaude-code-guide%2Fsmtp-penetration-testing%2F@1e87247f733b12febba246ac6b1d52a2fb0845582f1c0a4b322d5bb5be32411d
Security Audit — socket — smtp-penetration-testing