email-ops
Pass
Audited by Gen Agent Trust Hub on Apr 6, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted external data from email threads, creating a surface for indirect prompt injection.
- Ingestion points: Email thread content and history are retrieved during the triage and reply workflows (SKILL.md).
- Boundary markers: Absent. The instructions do not specify the use of delimiters or 'ignore' instructions to separate thread content from agent commands.
- Capability inventory: The skill instructions permit live-sending and drafting of messages based on processed thread context (SKILL.md).
- Sanitization: Absent. There is no instruction to validate, escape, or filter content retrieved from the mailbox surface before it is interpolated into drafts or send commands.
Audit Metadata