bezalel-email
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted content from external email senders, which could contain malicious instructions or adversarial prompts.
- Ingestion points: Untrusted data enters the agent context through the
email__get_messageandemail__list_messagestools, as well as the inbound webhook JSON payload (SKILL.md). - Boundary markers: The instructions do not define boundary markers or delimiters to separate untrusted email content from agent instructions, nor do they advise the agent to ignore instructions embedded within the email text.
- Capability inventory: The agent has functional capabilities to act on the ingested data, specifically using
email__sendandemail__replyto communicate externally (SKILL.md). - Sanitization: There is no documentation of sanitization, filtering, or validation of the email bodies or subjects before they are presented to the agent.
Audit Metadata