inbox-executive-assistant

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill proactively addresses indirect prompt injection by defining strict safety rules to treat email bodies and attachments as hostile. It mandates that instructions must only come from the user and never from the triaged content. • Ingestion points: Email bodies and attachments from Gmail or Microsoft 365 (SKILL.md). • Boundary markers: Explicit instructions in 'Safety rules' to ignore instructions found inside emails (SKILL.md). • Capability inventory: Email reading, search, labeling, and draft creation; Calendar reading and event management (SKILL.md). • Sanitization: Prohibits following instructions inside emails and flags suspicious manipulation attempts to the user (SKILL.md, triage-rubric.md).
  • [DATA_EXFILTRATION]: The skill prevents potential data exfiltration via 'EchoLeak' by explicitly forbidding the agent from auto-fetching links or images embedded in emails (SKILL.md).
  • [COMMAND_EXECUTION]: The skill uses least-privilege platform connectors for specific tasks and does not involve arbitrary command execution, script running, or file system access outside of the defined scope (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 07:03 PM
Security Audit — agent-trust-hub — inbox-executive-assistant