email-writing-frameworks
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to run the
@coldiq/mcppackage usingnpx. This package belongs to the skill's author, Cold-IQ. - [PROMPT_INJECTION]: The skill identifies an indirect prompt injection surface as it retrieves external data from social media and websites to populate email templates.
- Ingestion points: Data retrieved via
mcp__coldiq__extract_post_engagementandmcp__coldiq__fetch_page_contenttools. - Boundary markers: There are no specific delimiters or instructions to isolate the fetched external data from the surrounding prompt context.
- Capability inventory: The skill utilizes the agent's ability to call MCP tools to fetch and process data.
- Sanitization: No evidence of validation or sanitization of the external content before it is used in email generation was found.
Audit Metadata