magma-support

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted customer inquiries from external webhooks, which creates a surface for indirect prompt injection. An attacker could craft a malicious inquiry designed to influence the content of the drafted emails or attempt to manipulate the parameters of the CLI command. \n
  • Ingestion points: Customer inquiries received via webhooks mentioned in SKILL.md. \n
  • Boundary markers: No specific delimiters or safety instructions are used to isolate untrusted inquiries from the system prompt logic. \n
  • Capability inventory: Command execution via the 'gws' CLI for interacting with Gmail drafts. \n
  • Sanitization: No explicit input validation or sanitization of inquiry data is defined.
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to use the 'gws' (Google Workspace) CLI tool. While intended for legitimate business automation (creating drafts for human review), this provides the agent with the capability to execute shell commands and interact with the user's email environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 05:08 AM
Security Audit — agent-trust-hub — magma-support