Email Composer
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
- [NO_CODE]: The skill consists entirely of a markdown documentation file (SKILL.md) and does not include any executable scripts, binaries, or platform configurations.
- [SAFE]: No evidence of malicious patterns, credential theft, or unauthorized network operations was found in the instructions or examples.
- [PROMPT_INJECTION]: The skill identifies a workflow for processing untrusted email threads (Workflow 2), which constitutes a potential indirect prompt injection surface. However, the risk is negligible as the skill lacks any operational capabilities that could be leveraged for an attack. Evidence: 1. Ingestion points: Workflow 2 in SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: None. 4. Sanitization: Absent.
Audit Metadata