agent-mail
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPERSISTENCECREDENTIALS_UNSAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's messaging system creates a surface for indirect prompt injection by ingesting and processing content from other agents.\n
- Ingestion points: The
fetch_inbox,search_messages, andsummarize_threadtools inreferences/TOOLS.mdread message bodies (body_md).\n - Boundary markers: The instructions do not specify any delimiters or mandatory headers to prevent the agent from executing instructions embedded in messages.\n
- Capability inventory: The skill can execute local CLI commands via the
amtool, install git pre-commit hooks, and perform destructive database resets.\n - Sanitization: No sanitization or escaping requirements are defined for message content before it is processed by the agent.\n- [COMMAND_EXECUTION]: The skill uses a local CLI tool (
am) to perform management tasks. This includes a destructive operation,am clear-and-reset-everything --force, which irreversibly deletes the coordination database and all associated storage contents.\n- [PERSISTENCE]: Theinstall_precommit_guardfunction inreferences/TOOLS.mdinstalls a git pre-commit hook. This establishes local persistence for the skill's coordination logic, which will execute automatically during repository commit operations.\n- [CREDENTIALS_UNSAFE]:references/RECOVERY.mdreferences sensitive local file paths for cryptographic operations, such as~/.age/key.txtand./keys/signing.key. While these are part of a legitimate export and signing feature, they represent sensitive targets that could be targeted for exposure if the agent's logic is subverted.
Audit Metadata