email-composer
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user input for email drafting and has file-writing capabilities, representing a standard injection surface. Ingestion points: User-provided parameters (purpose, key points) in SKILL.md. Boundary markers: None. Capability inventory: Read, Write, and Edit tools. Sanitization: None.
- [SAFE]: The skill consists entirely of instructional markdown and email templates. It does not include any scripts, external dependencies, or network-enabled commands.
- [SAFE]: No obfuscation, prompt injection attempts, or persistence mechanisms were detected.
Audit Metadata