emails

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest data from external local files to gain context for its email generation tasks, which introduces a surface for indirect prompt injection.\n
  • Ingestion points: Instructions in SKILL.md direct the agent to read .agents/product-marketing.md, .claude/product-marketing.md, or product-marketing-context.md.\n
  • Boundary markers: There are no explicit delimiters or instructions provided to separate the ingested marketing data from the core system prompt or to warn the agent about potentially malicious instructions within those files.\n
  • Capability inventory: The skill's primary capabilities are limited to generating email copy and structuring sequences. It does not implement automated network requests or shell command execution based on the ingested content in the provided files.\n
  • Sanitization: No validation or sanitization logic is present to check the integrity or content of the external marketing context files before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 07:25 AM
Security Audit — agent-trust-hub — emails