Back to skill

Security audit

Gosmtp

Security checks across malware telemetry and agentic risk

Overview

This email-sending skill is review-worthy because it asks for SMTP credentials, includes a credential-like password in its documentation, and its built-in send command emails a fixed external recipient.

Do not use the included SMTP password. If you install or adapt this skill, replace it with your own scoped app password, verify every recipient before sending, and avoid running the built-in send command unless the hardcoded recipient has been removed.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.