mermail-cli
Pass
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing the
mermail-clipackage globally vianpm install -gor running it once usingnpx --yes. These commands download and execute code from an external package registry. - [COMMAND_EXECUTION]: The skill's primary purpose is to generate and execute shell commands and scripts. While it includes extensive safety guidelines, the ability to run terminal commands poses a risk if not carefully supervised.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from email mailboxes and threads, creating a surface for indirect prompt injection attacks.
- Ingestion points: Untrusted content is ingested from email bodies, subjects, headers, and thread context through commands like
mermail emails list,mermail emails wait, andmermail emails context(referenced inSKILL.mdandreferences/workflows.md). - Boundary markers: The instructions in
SKILL.mdandreferences/security.mdexplicitly state that email content should be treated as untrusted data rather than instructions, providing a defensive boundary. - Capability inventory: The skill can perform sensitive actions such as sending emails (
mermail emails send), creating mailboxes, and executing wallet transfers via shell commands. - Sanitization:
references/workflows.mdindicates that email thread context is sanitized and scan-gated before being processed.
Audit Metadata