agent-email-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill architecture is centered on processing untrusted inbound email, attachments, and webhook payloads. This represents a significant attack surface for indirect prompt injection, where malicious instructions embedded in email content could manipulate the agent's behavior.
- [EXTERNAL_DOWNLOADS]: The skill references the 'agentmail' SDK and 'svix' for webhook verification. These are recognized vendor resources and dependencies essential for the described functionality, including security-critical signature verification.
- [PROMPT_INJECTION]: A detection was noted for typical injection payloads (e.g., 'Ignore your previous instructions'); however, these are contained within documentation as examples of threats to mitigate, rather than malicious instructions from the skill itself.
Audit Metadata