agentmail-cli

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill enables the agent to fetch and process external, untrusted content from emails and threads. This creates an attack surface where malicious instructions hidden in email bodies could influence the agent's subsequent logic or tool usage.
  • Ingestion points: Message and thread retrieval commands (inboxes:messages get, inboxes:threads get) in SKILL.md.
  • Boundary markers: Absent. The instructions do not define delimiters or provide warnings to the agent to treat email content as data only.
  • Capability inventory: The skill allows the agent to send/reply/forward emails and configure infrastructure like webhooks and domains via CLI commands.
  • Sanitization: No sanitization or filtering logic is specified for the content of fetched messages.
  • [COMMAND_EXECUTION]: The skill operates by executing the agentmail CLI tool. It includes a specific safety instruction for the agent to confirm the identity of a resource before running the destructive delete command.
  • [EXTERNAL_DOWNLOADS]: The skill installs the agentmail-cli package via NPM. This is an official vendor resource consistent with the skill's stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 09:47 PM