email-drafter
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input (email context, recipient details, and specific points) to draft emails and has access to document creation tools, which creates a surface for potential indirect prompt injection attacks where malicious instructions could be embedded in the input data.
- Ingestion points: User-provided context, recipient relationship, and specific points to include as described in the "How to Use" section of SKILL.md.
- Boundary markers: None identified; the instructions lack explicit delimiters or guidance for the agent to ignore instructions embedded within the user's input.
- Capability inventory: Access to the
create_docxtool via theoffice-mcpserver as defined in the YAML frontmatter. - Sanitization: No sanitization, validation, or filtering of user-supplied data is specified in the skill instructions.
- [NO_CODE]: The skill consists entirely of Markdown instructions and YAML configuration. No scripts, binaries, or other executable code are included in the skill package.
Audit Metadata