skills/erphq/skills/email-resend/Gen Agent Trust Hub

email-resend

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill instructions specify the use of sensitive local configuration files at ~/.build-host/credentials.json. This access is functionally necessary for infrastructure management and is protected by explicit safety guidelines that prohibit the disclosure of credentials in outputs or chat history.
  • [COMMAND_EXECUTION]: The skill involves interacting with the build.host API to perform administrative tasks such as updating environment variables and triggering deployments. These operations are within the scope of the skill's primary purpose and are performed through the user's authenticated session.
  • [PROMPT_INJECTION]: The skill operates on user-provided project files and git repositories, creating a surface for indirect prompt injection. This risk is mitigated by specific safety rules that require verification of results and forbid the exposure of sensitive data encountered during repository inspection.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 04:43 PM
Security Audit — agent-trust-hub — email-resend