email-drafter

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input (email context, recipient details, and specific points) to draft emails and has access to document creation tools, which creates a surface for potential indirect prompt injection attacks where malicious instructions could be embedded in the input data.
  • Ingestion points: User-provided context, recipient relationship, and specific points to include as described in the "How to Use" section of SKILL.md.
  • Boundary markers: None identified; the instructions lack explicit delimiters or guidance for the agent to ignore instructions embedded within the user's input.
  • Capability inventory: Access to the create_docx tool via the office-mcp server as defined in the YAML frontmatter.
  • Sanitization: No sanitization, validation, or filtering of user-supplied data is specified in the skill instructions.
  • [NO_CODE]: The skill consists entirely of Markdown instructions and YAML configuration. No scripts, binaries, or other executable code are included in the skill package.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 08:53 PM
Security Audit — agent-trust-hub — email-drafter