resend-sending

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill incorporates a robust security contract for handling received email content. It defines clear ingestion points and mandates the use of boundary markers (<untrusted-content>) to ensure the agent treats external data as information rather than executable instructions. The agent is explicitly told to ignore instructions like 'ignore your previous instructions' found within processed mail.
  • [CREDENTIALS_UNSAFE]: The skill strictly forbids the agent from requesting or accepting API keys in the conversation. It relies on the agent-resend CLI tool to manage secrets in a secure, external store, ensuring that credentials never enter the LLM's context or conversation history.
  • [COMMAND_EXECUTION]: All email operations require a multi-step human-in-the-loop process (Prepare -> Preview -> Approval -> Execute). The agent-resend tool ensures that no email is sent without explicit user confirmation of the exact contents, recipients, and attachments.
  • [DATA_EXFILTRATION]: Attachment access is restricted to user-approved folders. The skill prevents unauthorized file access by requiring terminal-level configuration via agentcomms attach roots add to allow specific directories, preventing the agent from autonomously accessing sensitive system files.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 12:32 AM
Security Audit — agent-trust-hub — resend-sending