skills/boshu2/agentops/agent-mail/Gen Agent Trust Hub

agent-mail

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPERSISTENCECREDENTIALS_UNSAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's messaging system creates a surface for indirect prompt injection by ingesting and processing content from other agents.\n
  • Ingestion points: The fetch_inbox, search_messages, and summarize_thread tools in references/TOOLS.md read message bodies (body_md).\n
  • Boundary markers: The instructions do not specify any delimiters or mandatory headers to prevent the agent from executing instructions embedded in messages.\n
  • Capability inventory: The skill can execute local CLI commands via the am tool, install git pre-commit hooks, and perform destructive database resets.\n
  • Sanitization: No sanitization or escaping requirements are defined for message content before it is processed by the agent.\n- [COMMAND_EXECUTION]: The skill uses a local CLI tool (am) to perform management tasks. This includes a destructive operation, am clear-and-reset-everything --force, which irreversibly deletes the coordination database and all associated storage contents.\n- [PERSISTENCE]: The install_precommit_guard function in references/TOOLS.md installs a git pre-commit hook. This establishes local persistence for the skill's coordination logic, which will execute automatically during repository commit operations.\n- [CREDENTIALS_UNSAFE]: references/RECOVERY.md references sensitive local file paths for cryptographic operations, such as ~/.age/key.txt and ./keys/signing.key. While these are part of a legitimate export and signing feature, they represent sensitive targets that could be targeted for exposure if the agent's logic is subverted.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:34 AM
Security Audit — agent-trust-hub — agent-mail