email-connector
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a shell script
scripts/verify.shdesigned to lint codebases for security violations. The script performs read-only operations usingfindandgrepto detect hard-coded credentials, missing idempotency keys, and unverified webhook handlers. It does not execute remote code or perform destructive operations. - [CREDENTIALS_UNSAFE]: The skill actively promotes secure credential management. It explicitly warns against hard-coding API keys (e.g., Resend's
re_or SendGrid'sSG.prefixes) and provides instructions for sourcing them fromprocess.env. Thescripts/verify.shincludes regex patterns specifically to detect and block committed literals. - [SAFE]: The skill advocates for the use of React Email components to avoid manual string concatenation, which mitigates XSS risks when rendering user-supplied data in email bodies.
- [SAFE]: Instructions for implementing bounce and complaint webhooks require mandatory signature verification on the raw request body before parsing, protecting the application against spoofed events and suppression list poisoning.
Audit Metadata