mjml-email-templates
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The template rendering system in
MjmlTemplateRenderer.csprovides a surface for indirect prompt injection if variables contain untrusted external data. - Ingestion points: Data enters the system via the
variablesdictionary passed toRenderTemplateAsyncandComposeSignupInvitationAsyncinSKILL.md. - Boundary markers: The system uses
{{Variable}}delimiters for interpolation but lacks instructions to the rendering engine to ignore or escape special characters within the substituted content. - Capability inventory: The skill leverages the
Mjml.Netlibrary to compile MJML markup into responsive HTML bodies for email delivery. - Sanitization: The
SubstituteVariableshelper method performs direct replacement of placeholders with variable values without implementing HTML or MJML entity encoding, allowing for potential markup injection if input is not pre-sanitized by the application.
Audit Metadata