bezalel-email

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted content from external email senders, which could contain malicious instructions or adversarial prompts.
  • Ingestion points: Untrusted data enters the agent context through the email__get_message and email__list_messages tools, as well as the inbound webhook JSON payload (SKILL.md).
  • Boundary markers: The instructions do not define boundary markers or delimiters to separate untrusted email content from agent instructions, nor do they advise the agent to ignore instructions embedded within the email text.
  • Capability inventory: The agent has functional capabilities to act on the ingested data, specifically using email__send and email__reply to communicate externally (SKILL.md).
  • Sanitization: There is no documentation of sanitization, filtering, or validation of the email bodies or subjects before they are presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — bezalel-email