email-template-builder
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external data to generate email templates, creating a surface for indirect prompt injection.
- Ingestion points: emails/templates/welcome.tsx and emails/templates/invoice.tsx.
- Boundary markers: Absent; user-provided data is interpolated directly into component props.
- Capability inventory: Includes network operations through email provider adapters (emails/lib/send.ts) and file system reads within automation scripts (scripts/render_size_analyzer.py, scripts/spam_score_checker.py, scripts/template_validator.py).
- Sanitization: No explicit input sanitization or filtering logic for string variables is implemented beyond framework-level defaults.
- [EXTERNAL_DOWNLOADS]: Fetches font assets from Google's font registry (fonts.gstatic.com). This targets a well-known service for legitimate template styling.
Audit Metadata