extension-email-marketing
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides an interface for sending marketing emails where potentially untrusted data is ingested and processed, creating an attack surface for indirect instructions.
- Ingestion points: The
sendMarketingEmailfunction insrc/backend/main.moacceptssubjectandhtmlBodyarguments which are provided at runtime. - Boundary markers: There are no delimiters or explicit instructions to the agent to disregard embedded content within the
htmlBodyorsubjectfields. - Capability inventory: The skill utilizes
EmailClient.sendMarketingEmailto perform network operations by dispatching emails to external recipients. - Sanitization: The skill does not perform sanitization, validation, or escaping of the
htmlBodyorsubjectinputs before they are interpolated into the final email content.
Audit Metadata