inbox-zero-manager
Pass
Audited by Gen Agent Trust Hub on Apr 18, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill contains a surface for indirect prompt injection as it is designed to ingest and act upon untrusted external data.
- Ingestion points: The skill reads the latest messages from the user's inbox (SKILL.md).
- Boundary markers: There are no instructions or delimiters provided to ensure the agent ignores malicious instructions that might be embedded in emails.
- Capability inventory: The skill has the capability to read emails, draft replies, and create calendar events using integration tools.
- Sanitization: No sanitization, escaping, or validation of the email content is specified before the data is processed.
Audit Metadata