email-design

Pass

Audited by Gen Agent Trust Hub on May 9, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references Google Fonts via the @import directive in a CSS block. This is a standard practice for web and email design and utilizes a well-known, trusted service.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external inputs such as Figma URLs and design systems via the get_design_context tool. While this represents an ingestion point for untrusted data, the skill's capabilities are limited to generating HTML email code, posing minimal risk.
  • [SAFE]: All provided code snippets are standard HTML and CSS resets specifically tailored for email client compatibility (e.g., table-based layouts, MSO conditional comments for Outlook, and inline styling).
Audit Metadata
Risk Level
SAFE
Analyzed
May 9, 2026, 07:36 PM
Security Audit — agent-trust-hub — email-design