email-header-injection

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill provides instructions for the agent to function as an 'Expert email header injection and authentication bypass' guide. These instructions are pedagogical, intended for security analysis and testing, and do not attempt to override platform safety filters or core operating principles.
  • [DATA_EXFILTRATION]: The content describes various techniques for data exfiltration through email, such as Bcc injection and CSS-based data exfiltration. These are included as illustrative examples of vulnerabilities for security professionals to identify and remediate, not as active exfiltration attempts by the skill itself.
  • [COMMAND_EXECUTION]: The skill mentions the use of the dig command for DNS reconnaissance related to SPF, DKIM, and DMARC records. This is standard diagnostic behavior for security testing and does not involve unauthorized command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 01:23 PM
Security Audit — agent-trust-hub — email-header-injection