extension-email-verification
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The example implementation in
src/backend/main.modemonstrates a pattern where untrusted user input is interpolated into data sent to an external service (email client) without sanitization. - Ingestion points: The
registerUser(email : Text, name : Text)function insrc/backend/main.moaccepts thenameparameter directly from the caller. - Boundary markers: There are no boundary markers or delimiters used to separate the user-provided
namefrom the surrounding HTML template. - Capability inventory: The skill uses
EmailClient.sendVerificationEmail(insrc/backend/main.mo) to send content to external recipients. - Sanitization: Absent. The
namevariable is concatenated directly into the HTML string:"Hello " # name # ",<br><br>". This allows a malicious user to inject arbitrary HTML tags or scripts into the verification email sent to the provided address.
Audit Metadata