emails

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it instructs the agent to read and trust content from local project files to provide context for its email generation tasks.
  • Ingestion points: In SKILL.md, the agent is directed to read .agents/product-marketing.md, .claude/product-marketing.md, or product-marketing-context.md before proceeding with the task.
  • Boundary markers: The instructions do not define any delimiters or provide warnings for the agent to ignore potential instructions embedded within these external marketing context files.
  • Capability inventory: While primarily a text-generation skill, it references integrations with multiple email automation platforms (Customer.io, Mailchimp, Resend, etc.) that could be targeted by malicious instructions in the context files.
  • Sanitization: There is no evidence of sanitization or validation of the input data from the local project files before it is used to influence the agent's output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:47 AM
Security Audit — agent-trust-hub — emails