email-template-builder

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external data to generate email templates, creating a surface for indirect prompt injection.
  • Ingestion points: emails/templates/welcome.tsx and emails/templates/invoice.tsx.
  • Boundary markers: Absent; user-provided data is interpolated directly into component props.
  • Capability inventory: Includes network operations through email provider adapters (emails/lib/send.ts) and file system reads within automation scripts (scripts/render_size_analyzer.py, scripts/spam_score_checker.py, scripts/template_validator.py).
  • Sanitization: No explicit input sanitization or filtering logic for string variables is implemented beyond framework-level defaults.
  • [EXTERNAL_DOWNLOADS]: Fetches font assets from Google's font registry (fonts.gstatic.com). This targets a well-known service for legitimate template styling.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 08:17 PM
Security Audit — agent-trust-hub — email-template-builder