inbox-zero-manager

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains a surface for indirect prompt injection as it is designed to ingest and act upon untrusted external data.
  • Ingestion points: The skill reads the latest messages from the user's inbox (SKILL.md).
  • Boundary markers: There are no instructions or delimiters provided to ensure the agent ignores malicious instructions that might be embedded in emails.
  • Capability inventory: The skill has the capability to read emails, draft replies, and create calendar events using integration tools.
  • Sanitization: No sanitization, escaping, or validation of the email content is specified before the data is processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 04:43 PM
Security Audit — agent-trust-hub — inbox-zero-manager