email-marketing

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill relies on interpolating variables (such as {first_name}, {product}, and {testimonial}) into email templates. This creates a vulnerability surface where untrusted data from external sources, such as a CRM or database, could contain malicious instructions designed to influence the agent's behavior during generation or target recipients.
  • Ingestion points: Variables used in the sequences and promotional templates within SKILL.md (e.g., {first_name}, {cart_items_with_images}, {personalized_stats}).
  • Boundary markers: Absent; the templates do not include specific instructions to the agent to disregard instructions potentially contained within the placeholder data.
  • Capability inventory: The skill utilizes tools for external communication, specifically mailchimp_send, sendgrid_campaign, and klaviyo_flow via the email-mcp server.
  • Sanitization: The instructions do not define any validation or escaping mechanisms for the data used in template placeholders.
  • [SAFE]: The skill references mxtoolbox.com in the deliverability section for domain authentication checks; this is a well-known service for legitimate infrastructure maintenance.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:46 PM
Security Audit — agent-trust-hub — email-marketing