resend-reading

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill operates on a least-privilege basis by restricting the agent to read-only operations despite the API key potentially having broader permissions. It also enforces a strict security protocol for managing Resend API keys, ensuring they are never handled in chat and are instead managed via the user's terminal.
  • [INDIRECT_PROMPT_INJECTION]: The skill correctly identifies and mitigates risks associated with processing untrusted email content. 1. Ingestion points: resend_received_list, resend_received_show, and resend_emails_list. 2. Boundary markers: External content is wrapped in <untrusted-content> tags. 3. Capability inventory: Minimal capabilities including file-write (downloading attachments to a restricted 'out' folder) and read-only account access. 4. Sanitization: Hidden text is stripped and the agent is explicitly instructed to disregard any instructions found within email bodies.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 12:33 AM
Security Audit — agent-trust-hub — resend-reading