messages-ops

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external messaging platforms.
  • Ingestion points: Live message threads, iMessage, SMS/texts, and social media DMs retrieved from local or browser-gated surfaces as described in SKILL.md.
  • Boundary markers: The instructions lack specific delimiters or "ignore embedded instructions" warnings to prevent the agent from accidentally executing instructions found within user messages.
  • Capability inventory: The skill allows for the retrieval, inspection, and summarization of message content, as well as the preparation of reply drafts.
  • Sanitization: No sanitization, filtering, or escaping of the message content is mentioned before it is processed or presented to the user.
  • [NO_CODE]: This skill contains only markdown instructions and configuration metadata. There are no executable scripts, binaries, or complex automation logic provided for technical auditing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:41 PM
Security Audit — agent-trust-hub — messages-ops