testing-for-email-header-injection

Pass

Audited by Gen Agent Trust Hub on Mar 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: No malicious behavior, prompt injection, or data exfiltration attempts were identified within the skill files. The tool's behavior aligns with its stated purpose as a security testing utility.
  • [COMMAND_EXECUTION]: The SKILL.md file contains several curl command examples intended for manual security testing of web application endpoints to verify SMTP header injection vulnerabilities.
  • [EXTERNAL_DOWNLOADS]: The scripts/agent.py script utilizes the requests library to perform automated network communication with target servers, which is necessary for its function as a vulnerability scanner.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 15, 2026, 01:51 PM