bub-email-triage
Pass
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted external data from emails and calendar invites, which creates a potential indirect prompt injection surface.
- Ingestion points: Inbound email and calendar notification content.
- Boundary markers: Absent; there are no explicit delimiters or instructions to ignore embedded prompts in the external data.
- Capability inventory: The skill can summarize and forward content to another agent (agent:main:main).
- Sanitization: Absent; the workflow does not mention sanitizing or escaping the content from external sources before interpolation.
Audit Metadata