extension-email-verification

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The example implementation in src/backend/main.mo demonstrates a pattern where untrusted user input is interpolated into data sent to an external service (email client) without sanitization.
  • Ingestion points: The registerUser(email : Text, name : Text) function in src/backend/main.mo accepts the name parameter directly from the caller.
  • Boundary markers: There are no boundary markers or delimiters used to separate the user-provided name from the surrounding HTML template.
  • Capability inventory: The skill uses EmailClient.sendVerificationEmail (in src/backend/main.mo) to send content to external recipients.
  • Sanitization: Absent. The name variable is concatenated directly into the HTML string: "Hello " # name # ",<br><br>". This allows a malicious user to inject arbitrary HTML tags or scripts into the verification email sent to the provided address.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 04:05 PM
Security Audit — agent-trust-hub — extension-email-verification