agentmail-cli

Fail

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill specifies the package 'agentmail-cli' for installation. This name fails to match known legitimate patterns like 'agentmail-to-*' provided for the AgentMail vendor, suggesting a potential typosquatting or impersonation attack.
  • [COMMAND_EXECUTION]: The skill routinely invokes shell commands to perform email management tasks.
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves text from external inboxes and messages. Because this data is untrusted and the skill provides no sanitization or safety boundary instructions, it is vulnerable to indirect prompt injection from malicious senders.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 8, 2026, 11:31 PM
Security Audit — agent-trust-hub — agentmail-cli