email-connector

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a shell script scripts/verify.sh designed to lint codebases for security violations. The script performs read-only operations using find and grep to detect hard-coded credentials, missing idempotency keys, and unverified webhook handlers. It does not execute remote code or perform destructive operations.
  • [CREDENTIALS_UNSAFE]: The skill actively promotes secure credential management. It explicitly warns against hard-coding API keys (e.g., Resend's re_ or SendGrid's SG. prefixes) and provides instructions for sourcing them from process.env. The scripts/verify.sh includes regex patterns specifically to detect and block committed literals.
  • [SAFE]: The skill advocates for the use of React Email components to avoid manual string concatenation, which mitigates XSS risks when rendering user-supplied data in email bodies.
  • [SAFE]: Instructions for implementing bounce and complaint webhooks require mandatory signature verification on the raw request body before parsing, protecting the application against spoofed events and suppression list poisoning.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:36 PM
Security Audit — agent-trust-hub — email-connector