mjml-email-templates

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The template rendering system in MjmlTemplateRenderer.cs provides a surface for indirect prompt injection if variables contain untrusted external data.
  • Ingestion points: Data enters the system via the variables dictionary passed to RenderTemplateAsync and ComposeSignupInvitationAsync in SKILL.md.
  • Boundary markers: The system uses {{Variable}} delimiters for interpolation but lacks instructions to the rendering engine to ignore or escape special characters within the substituted content.
  • Capability inventory: The skill leverages the Mjml.Net library to compile MJML markup into responsive HTML bodies for email delivery.
  • Sanitization: The SubstituteVariables helper method performs direct replacement of placeholders with variable values without implementing HTML or MJML entity encoding, allowing for potential markup injection if input is not pre-sanitized by the application.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:35 PM
Security Audit — agent-trust-hub — mjml-email-templates