messages-ops
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external messaging platforms.
- Ingestion points: Live message threads, iMessage, SMS/texts, and social media DMs retrieved from local or browser-gated surfaces as described in SKILL.md.
- Boundary markers: The instructions lack specific delimiters or "ignore embedded instructions" warnings to prevent the agent from accidentally executing instructions found within user messages.
- Capability inventory: The skill allows for the retrieval, inspection, and summarization of message content, as well as the preparation of reply drafts.
- Sanitization: No sanitization, filtering, or escaping of the message content is mentioned before it is processed or presented to the user.
- [NO_CODE]: This skill contains only markdown instructions and configuration metadata. There are no executable scripts, binaries, or complex automation logic provided for technical auditing.
Audit Metadata