resend-sending
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill incorporates a robust security contract for handling received email content. It defines clear ingestion points and mandates the use of boundary markers (
<untrusted-content>) to ensure the agent treats external data as information rather than executable instructions. The agent is explicitly told to ignore instructions like 'ignore your previous instructions' found within processed mail. - [CREDENTIALS_UNSAFE]: The skill strictly forbids the agent from requesting or accepting API keys in the conversation. It relies on the
agent-resendCLI tool to manage secrets in a secure, external store, ensuring that credentials never enter the LLM's context or conversation history. - [COMMAND_EXECUTION]: All email operations require a multi-step human-in-the-loop process (Prepare -> Preview -> Approval -> Execute). The
agent-resendtool ensures that no email is sent without explicit user confirmation of the exact contents, recipients, and attachments. - [DATA_EXFILTRATION]: Attachment access is restricted to user-approved folders. The skill prevents unauthorized file access by requiring terminal-level configuration via
agentcomms attach roots addto allow specific directories, preventing the agent from autonomously accessing sensitive system files.
Audit Metadata