testing-for-email-header-injection

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is internally consistent as a penetration-testing guide, but it equips an AI agent with explicit offensive security procedures that can exploit real email systems, relay spam, and siphon email copies or reset tokens. Install trust is low concern; the primary risk is enabling active exploitation.

Confidence: 93%Severity: 86%
Audit Metadata
Analyzed At
Mar 15, 2026, 01:54 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Ftesting-for-email-header-injection%2F@6d9b3935bbee2c8daa8be367991325b44dfdb76e