c-email
Pass
Audited by Gen Agent Trust Hub on Mar 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONNO_CODE
Full Analysis
- [SAFE]: The skill consists of documentation for legitimate email management tools. No obfuscation, data exfiltration, or malicious commands were found during analysis.
- [COMMAND_EXECUTION]: The skill documentation describes the use of
gogandhimalayato perform email-related tasks such as reading, searching, and sending messages. These commands are consistent with the skill's intended use case. - [PROMPT_INJECTION]: The skill provides the ability to read untrusted data from emails, which introduces an indirect prompt injection attack surface.
- Ingestion points: Untrusted email content is ingested via
gog mail readandhimalaya readas shown inSKILL.md. - Boundary markers: The skill does not define specific markers or instructions to separate email content from agent instructions.
- Capability inventory: The skill allows for various email operations, including sending, replying, and folder management.
- Sanitization: No evidence of content sanitization or validation was found in the skill's instructions.
- [NO_CODE]: The skill contains no executable scripts or binaries, relying solely on markdown-based documentation for its functionality.
Audit Metadata