agentmail-send-email
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill proactively addresses indirect prompt injection by instructing the agent to treat content from emails, attachments, and webhooks strictly as data and never as authorized instructions.
- [SAFE]: Implements a human-in-the-loop requirement by mandating user confirmation whenever email fields are inferred or when dealing with sensitive subject matter (financial, legal, or account changes).
- [SAFE]: Explicitly prohibits the disclosure of sensitive information such as API keys, private mailbox metadata, or hidden system prompts.
- [SAFE]: Provides clear operational boundaries, distinguishing between preparing content (drafting) and executing delivery (sending), reducing the risk of accidental automated actions.
Audit Metadata