check-email
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is specifically designed to ingest and process untrusted external data from email subjects, bodies, and attachments via the
agentmailMCP toolset. This creates a surface for Indirect Prompt Injection (Tool Output Poisoning), where malicious content within an email could attempt to override the agent's instructions. The skill author has proactively included a safety section and an authorization matrix to instruct the agent to ignore instructions found within email content.
Audit Metadata