sendgrid-automation

Pass

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the configuration of a remote Model Context Protocol (MCP) server at https://rube.app/mcp. This connects the agent to external infrastructure hosted on the Rube platform to facilitate tool execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the SendGrid API which could contain malicious instructions designed to influence agent behavior.
  • Ingestion points: External data is ingested via SENDGRID_RETRIEVE_ALL_LISTS (list metadata), SENDGRID_GET_CONTACTS_BY_EMAILS (contact records), and SENDGRID_FILTER_ALL_MESSAGES (email activity/content logs).
  • Boundary markers: The instructions do not define delimiters or warnings to treat external data as untrusted content.
  • Capability inventory: The skill possesses sensitive capabilities including sending emails (SENDGRID_CREATE_SINGLE_SEND), modifying contact databases (SENDGRID_ADD_OR_UPDATE_A_CONTACT), and deleting resources (SENDGRID_REMOVE_LIST_AND_OPTIONAL_CONTACTS).
  • Sanitization: There are no instructions for sanitizing or escaping content retrieved from SendGrid before it is integrated into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 8, 2026, 09:51 PM