Agent skill

Test Email Channel Security

by cyberful in cyberful/cyberful

Test application email generation, recipient authority, template and header construction, link and token binding, inbound parsing, threading, reply handling, bounce processing, and tenant isolation.

AGPL-3.0Auto-check passedBackend & APIs

Install Test Email Channel Security

skills CLI
$ npx skills add cyberful/cyberful --skill test-email-channel-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cyberful/cyberful test-email-channel-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cyberful/cyberful.git skills-src && mkdir -p .claude/skills && cp -r skills-src/cyberful/builtin/skills/test-email-channel-security .claude/skills/test-email-channel-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
test-email-channel-security
GitHub stars
135
Token cost
~599 tokens
SKILL.md length
162 words
Files
5 (incl. references, assets)
Skills in repo
85
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Test application email generation, recipient authority, template and header construction, link and token binding, inbound parsing, threading, reply handling, bounce processing, and tenant isolation.

  • Email header injection
  • SKILL.md covers Build the channel matrix, Test discriminating controls and Confirmation standard
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Template confusion

What it does

Test Email Channel Security is an agent skill from cyberful/cyberful. Test application email generation, recipient authority, template and header construction, link and token binding, inbound parsing, threading, reply handling, bounce processing, and tenant isolation. Use for email header injection, misdelivery, template confusion, reply-to abuse, magic-link leakage, inbound-email authorization, or security-notification integrity.

Its SKILL.md is about 600 tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files and assets (for example `agents/openai.yaml`, `assets/email-channel-matrix.example.json` and `assets/email-channel-matrix.schema.json`).

It sits in Backend & APIs, covering Authentication and Multi-tenancy. The repository describes itself as: Cyberful is an open-source AI Red Team for discovering, exploiting, verifying, and remediating vulnerabilities. The licence is AGPL-3.0.

When your agent uses it

  • Email header injection
  • Template confusion
  • Magic-link leakage
  • Inbound-email authorization

Example prompts

  • “/test-email-channel-security”

What it can do on your machine

Read from SKILL.md and the folder at commit ec598a6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Test Email Channel Security loads about 599 tokens when it runs, and up to ~881 if it reads all its reference files. Until then it costs about 98 tokens; SKILL.md has 162 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~599
With references · SKILL.md plus every file in references/, read only if the agent opens them
~881

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cyberful/cyberful at commit ec598a6, republished under its AGPL-3.0 licence (© cyberful). 162 words, ~599 tokens.

Download SKILL.mdSave it as .claude/skills/test-email-channel-security/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
test-email-channel-security
description
Test application email generation, recipient authority, template and header construction, link and token binding, inbound parsing, threading, reply handling, bounce processing, and tenant isolation. Use for email header injection, misdelivery, template confusion, reply-to abuse, magic-link leakage, inbound-email authorization, or security-notification integrity.
metadata.domain
application-security
metadata.subdomain
email-channel-security
metadata.triggers
email header injection, email recipient authorization, magic link security, inbound email processing, email template injection, reply handling security
metadata.tags
email, recipient-binding, header-injection, magic-link, inbound-parser, notification

Test Email Channel Security

Treat email as an asynchronous, multi-parser security channel. Separate application construction, provider transformation, mailbox display, link handling, replies, bounces, and inbound ingestion; each boundary has different identity and parsing rules.

Build the channel matrix

Use assets/email-channel-matrix.example.json with assets/email-channel-matrix.schema.json. Record trigger, actor, tenant, recipient derivation, sender identity, reply route, template, sensitive fields, links or tokens, provider, inbound correlation, retention, and evidence.

Read references/email-boundary-model.md. Use only controlled mailboxes and inert markers. Never deliver unsolicited messages or include real secrets in test content.

Test discriminating controls

Vary one of recipient authority, display data, header-capable input, template context, locale, threading identifiers, reply address, link host, token audience, expiry, forwarding, bounce identity, or inbound sender proof. Verify the actual rendered MIME and final controlled mailbox representation.

Confirmation standard

Report application trigger, recipient derivation, exact MIME or inbound artifact, parser boundary, current authorization, token or link binding, matched control, delivery or action effect, and affected tenant. Cosmetic rendering differences alone are not security findings.

© cyberful, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references, assets) in cyberful/builtin/skills/test-email-channel-security of cyberful/cyberful.

  • SKILL.md
  • agents/openai.yaml
  • assets/email-channel-matrix.example.json
  • assets/email-channel-matrix.schema.json
  • references/email-boundary-model.md

Open the folder on GitHubat commit ec598a6

Compare with similar skills

Test Email Channel Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Test Email Channel Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Test Email Channel Security this skillcyberful/cyberful135—~599Automated safety check: PassAGPL-3.0
Supercheck Security Authsupercheck-io/supercheck215—~1.2kAutomated safety check: PassAGPL-3.0
Clerk Orgsgrowupanand/ConvoForm102—~5.4kAutomated safety check: PassMIT
API Authcyanheads/pubmed-mcp-server158—~2.9kAutomated safety check: PassApache-2.0
Clerk Orgsgeekskai/blog103—~4.8kAutomated safety check: PassMIT
Clerk Reference Architecturejeremylongshore/tons-of-skills-marketplace2.8k—~1.9kAutomated safety check: PassMIT

Similar skills

  • Supercheck Security Auth

    supercheck-io/supercheck

    Work on Supercheck authentication, RBAC, tenant isolation, sessions, API and trigger keys, invitations, project membership, project variables, OAuth, super-admin behavior, SSRF, or…

    215 GitHub stars~1.2k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Clerk Orgs

    growupanand/ConvoForm

    Clerk Organizations for B2B and multi-tenant apps - org switching, roles and permissions, verified domains, and enterprise SSO.

    102 GitHub stars~5.4k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • API Auth

    cyanheads/pubmed-mcp-server

    Authentication, authorization, and multi-tenancy patterns for @cyanheads/mcp-ts-core.

    158 GitHub stars~2.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Clerk Orgs

    geekskai/blog

    Clerk Organizations for B2B SaaS - create multi-tenant apps with org switching, role-based access, verified domains, and enterprise SSO.

    103 GitHub stars~4.8k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Clerk Reference Architecture

    jeremylongshore/tons-of-skills-marketplace

    Reference architecture patterns for Clerk authentication. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~1.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Supabase Architecture Variants

    jeremylongshore/tons-of-skills-marketplace

    A skill your agent uses when choosing how to integrate Supabase into a specific stack — setting up Next.js SSR auth flows, wiring an SPA or React Native client, configuring mobile deep links, or…

    2.8k GitHub stars~1.9k tokensUpdated today
    Backend & APIsAuto-check passed

More from cyberful/cyberful

All 85 skills in this repo
  • Audit infrastructure-as-code artifacts for unsafe defaults, policy gaps, privilege exposure, control drift, and deployment-impact evidence.

    135 GitHub stars~649 tokensUpdated 1 mo ago
    Auto-check passed
  • Audit Kubernetes admission and policy-as-code enforcement against local workload manifests, exception paths, namespace scope, and deployment evidence.

    135 GitHub stars~610 tokensUpdated 1 mo ago
    Auto-check passed
  • Audit PCI DSS penetration-test methodology, scope, internal and external reports, segmentation results, tester independence, remediation, retesting, retention, and multi-tenant support evidence.

    135 GitHub stars~1k tokensUpdated 1 mo ago
    Auto-check passed
  • Operate Content Discovery

    cyberful/cyberful

    Design and interpret advanced content discovery with ffuf and complementary web fuzzers.

    135 GitHub stars~1.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Operate Network Recon

    cyberful/cyberful

    Build a high-fidelity network and service inventory using Nmap, Masscan, packet capture, DNS, and protocol-specific follow-up.

    135 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Operate Sast Toolchain

    cyberful/cyberful

    Operate Semgrep and source-oriented static analysis as a hypothesis, coverage, and regression system during advanced code audits.

    135 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Test Email Channel Security

What does Test Email Channel Security do?

Test application email generation, recipient authority, template and header construction, link and token binding, inbound parsing, threading, reply handling, bounce processing, and tenant isolation. Test Email Channel Security is an agent skill from cyberful/cyberful. Test application email generation, recipient authority, template and header construction, link and token binding, inbound parsing, threading, reply handling, bounce processing, and tenant isolation.

When should I use Test Email Channel Security?

Test Email Channel Security fits situations like: email header injection; template confusion; magic-link leakage; inbound-email authorization.

How do I install Test Email Channel Security in Claude Code?

Run `npx skills add cyberful/cyberful --skill test-email-channel-security -a claude-code`. Or copy the skill folder (cyberful/builtin/skills/test-email-channel-security in cyberful/cyberful) into .claude/skills/test-email-channel-security in your project. Claude Code loads it when a task matches its description.

How do I install Test Email Channel Security in Codex?

Run `npx skills add cyberful/cyberful --skill test-email-channel-security -a codex`. Or copy the skill folder (cyberful/builtin/skills/test-email-channel-security in cyberful/cyberful) into .agents/skills/test-email-channel-security in your project. Codex loads it when a task matches its description.

Can I use Test Email Channel Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cyberful/cyberful --skill test-email-channel-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/test-email-channel-security, .gemini/skills/test-email-channel-security, .github/skills/test-email-channel-security and .opencode/skills/test-email-channel-security in your project.

What does Test Email Channel Security need to run?

SKILL.md names no scripts, command-line tools or credentials: Test Email Channel Security is instructions for the agent only.

Does Test Email Channel Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Test Email Channel Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Test Email Channel Security use?

Test Email Channel Security is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Test Email Channel Security use?

About 599 tokens (SKILL.md is roughly 2.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 282 tokens, read only when the agent opens those files.

What are the alternatives to Test Email Channel Security?

Skills that share tags, products or a category with Test Email Channel Security: Supercheck Security Auth (supercheck-io/supercheck, 215 stars), Clerk Orgs (growupanand/ConvoForm, 102 stars), API Auth (cyanheads/pubmed-mcp-server, 158 stars) and Clerk Orgs (geekskai/blog, 103 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Test Email Channel Security?

cyberful (a GitHub organization) maintains it in cyberful/cyberful, which has 135 GitHub stars. The repository holds 85 skills in this directory. The repository was last updated on August 24, 2026.

Source: cyberful/cyberful on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.