emails
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it instructs the agent to read and trust content from local project files to provide context for its email generation tasks.
- Ingestion points: In
SKILL.md, the agent is directed to read.agents/product-marketing.md,.claude/product-marketing.md, orproduct-marketing-context.mdbefore proceeding with the task. - Boundary markers: The instructions do not define any delimiters or provide warnings for the agent to ignore potential instructions embedded within these external marketing context files.
- Capability inventory: While primarily a text-generation skill, it references integrations with multiple email automation platforms (Customer.io, Mailchimp, Resend, etc.) that could be targeted by malicious instructions in the context files.
- Sanitization: There is no evidence of sanitization or validation of the input data from the local project files before it is used to influence the agent's output.
Audit Metadata