extension-email-marketing

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides an interface for sending marketing emails where potentially untrusted data is ingested and processed, creating an attack surface for indirect instructions.
  • Ingestion points: The sendMarketingEmail function in src/backend/main.mo accepts subject and htmlBody arguments which are provided at runtime.
  • Boundary markers: There are no delimiters or explicit instructions to the agent to disregard embedded content within the htmlBody or subject fields.
  • Capability inventory: The skill utilizes EmailClient.sendMarketingEmail to perform network operations by dispatching emails to external recipients.
  • Sanitization: The skill does not perform sanitization, validation, or escaping of the htmlBody or subject inputs before they are interpolated into the final email content.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 04:05 PM
Security Audit — agent-trust-hub — extension-email-marketing