deliverability-qa
Pass
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes shell commands to execute local Python scripts (
resend.pyanddoh.py) to retrieve domain and DNS information.\n - Evidence: Found in
SKILL.mdunder 'Zero-dependency ESP automation' and 'Zero-dependency S1 record pull'.\n- [PROMPT_INJECTION]: The skill processes untrusted external data which presents a surface for indirect prompt injection attacks.\n - Ingestion points: Reads data from DNS exports, DMARC aggregate (RUA) reports, seed-list tests, ESP deliverability reports, and campaign creative HTML files.\n
- Boundary markers: Instructions explicitly advise the agent to treat all exported files and pasted HTML as untrusted content and to ignore any commands embedded within the text of the reports.\n
- Capability inventory: The skill can execute shell commands via Python scripts and write data to the local
memory/directory.\n - Sanitization: The agent is instructed to treat text inside reports strictly as evidence rather than instructions.
Audit Metadata