Suspicious Email Analyzer

Pass

Audited by Gen Agent Trust Hub on Jun 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of Markdown instructions and documentation. No scripts, binaries, or executable code are included in the package.
  • [SAFE]: All external references, such as URLs and email addresses (e.g., reportphishing@apwg.org), are directed towards legitimate security reporting channels or used as educational examples of phishing tactics.
  • [PROMPT_INJECTION]: The skill is designed to process untrusted external data (email content), which presents a surface for indirect prompt injection. However, given the lack of system capabilities, this risk is purely informational.
  • Ingestion points: Sender, subject, body, and links provided by the user for analysis in SKILL.md.
  • Boundary markers: None defined; there are no instructions to use delimiters or ignore instructions embedded within the analyzed email text.
  • Capability inventory: None; the skill does not request or use any tools for file access, network operations, or command execution.
  • Sanitization: None specified for the input data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 3, 2026, 02:52 PM
Security Audit — agent-trust-hub — Suspicious Email Analyzer