email-header-injection
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill provides instructions for the agent to function as an 'Expert email header injection and authentication bypass' guide. These instructions are pedagogical, intended for security analysis and testing, and do not attempt to override platform safety filters or core operating principles.
- [DATA_EXFILTRATION]: The content describes various techniques for data exfiltration through email, such as Bcc injection and CSS-based data exfiltration. These are included as illustrative examples of vulnerabilities for security professionals to identify and remediate, not as active exfiltration attempts by the skill itself.
- [COMMAND_EXECUTION]: The skill mentions the use of the
digcommand for DNS reconnaissance related to SPF, DKIM, and DMARC records. This is standard diagnostic behavior for security testing and does not involve unauthorized command execution.
Audit Metadata