email-header-injection

Pass

Audited by ZeroLeaks on Apr 16, 2026

Risk Level: LOW
Scan Summary

This skill looks clean overall, with low confidence. The skill has 1 transparency concern that weaken pre-use reviewability, mainly around potential hardcoded credential. The scanned skill keeps data and instructions reasonably separate and does not strongly encourage the agent to treat external content as policy. Behavior analysis was not run.

Score
82/100
Verdict
PASS
Confidence
low
Findings
1
Section Analysis (3)
TransparencyWARNING
61/100

The skill has 1 transparency concern that weaken pre-use reviewability, mainly around potential hardcoded credential.

Prompt InjectionPASS
92/100

The scanned skill keeps data and instructions reasonably separate and does not strongly encourage the agent to treat external content as policy.

Agent BehaviorSkipped

Behavior analysis was not run.

Findings (1)
CRITICAL

Potential hardcoded credential

Coverage DetailsClick to expand
Discovered Files
1
Omitted Files
0
Analyzed Bytes
10.7 KB
Sections Completed
2
Sections Skipped
1
Behavior Probes
0/0
Audit Metadata
Score
82/100
Verdict
PASS
Confidence
low
Sections
2/3 completed
Findings
1
Mode
risk
Files Scanned
1
Duration
0.1s
Analyzed
Apr 16, 2026, 08:56 AM
Security Audit — zeroleaks — email-header-injection