zoho-mail
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill retrieves untrusted email content from external accounts, which could contain malicious instructions designed to influence the agent's behavior. Ingestion points: email body and search result endpoints defined in SKILL.md (e.g., /messages/{messageId}/content). Boundary markers: None defined in the skill instructions. Capability inventory: The skill allows the agent to send, delete, and manage emails and folders. Sanitization: No sanitization or filtering of the retrieved email text is specified.
- [DATA_EXFILTRATION]: The skill is designed to access and retrieve sensitive user information, including private email messages and account metadata, which is its primary purpose. Evidence: Documentation in SKILL.md details how to retrieve message content, download attachments, and search through all user emails.
Audit Metadata