emaildesignskill
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data such as email HTML source code, React components, and template files, which represent a potential surface for indirect prompt injection.
- Ingestion points: Identified in SKILL.md and references/operating-checklist.md as raw HTML, React Email components, ESP templates, and Figma concepts.
- Boundary markers: The skill instructions do not define specific delimiters or instructions to ignore embedded commands within the ingested content.
- Capability inventory: The skill is strictly instructional and does not invoke any shell tools, network utilities, or file-writing capabilities, minimizing the impact of potential injections.
- Sanitization: No explicit sanitization or filtering of the ingested content is performed.
- [SAFE]: The skill relies on static markdown instructions and YAML configuration for guidance. No command execution, remote code downloads, privilege escalation, or persistence mechanisms were detected across the analyzed files.
Audit Metadata