mermail-cli

Pass

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing the mermail-cli package globally via npm install -g or running it once using npx --yes. These commands download and execute code from an external package registry.
  • [COMMAND_EXECUTION]: The skill's primary purpose is to generate and execute shell commands and scripts. While it includes extensive safety guidelines, the ability to run terminal commands poses a risk if not carefully supervised.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from email mailboxes and threads, creating a surface for indirect prompt injection attacks.
  • Ingestion points: Untrusted content is ingested from email bodies, subjects, headers, and thread context through commands like mermail emails list, mermail emails wait, and mermail emails context (referenced in SKILL.md and references/workflows.md).
  • Boundary markers: The instructions in SKILL.md and references/security.md explicitly state that email content should be treated as untrusted data rather than instructions, providing a defensive boundary.
  • Capability inventory: The skill can perform sensitive actions such as sending emails (mermail emails send), creating mailboxes, and executing wallet transfers via shell commands.
  • Sanitization: references/workflows.md indicates that email thread context is sanitized and scan-gated before being processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 6, 2026, 08:00 AM