follow-up-chaser
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill proactively addresses indirect prompt injection risks by instructing the agent to treat all inbound email content as hostile and to ignore any instructions embedded within the threads.
- [DATA_EXFILTRATION]: It contains a specific safety rule against auto-fetching links or images within email threads, explicitly citing the prevention of exfiltration paths.
- [COMMAND_EXECUTION]: The skill operates under a strict "Draft-only" policy, ensuring it cannot autonomously send emails. It relies on standard, authorized connectors for Gmail, Microsoft 365, and Google Calendar.
- [SAFE]: The skill uses a transparent "nudge ladder" in its references to govern the timing and tone of drafts, with clear constraints to prevent aggressive or inappropriate messaging.
Audit Metadata