skills/frumu-ai/tandem/email-digest/Gen Agent Trust Hub

email-digest

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The provided configuration files (SKILL.md, automation.example.yaml, and workflow.yaml) do not contain any malicious code, obfuscated instructions, or evidence of unauthorized resource access.
  • [PROMPT_INJECTION]: The skill is designed to process untrusted content from incoming emails, which constitutes an attack surface for indirect prompt injection. 1. Ingestion points: Incoming emails are fetched via the gmail_read tool as defined in SKILL.md. 2. Boundary markers: The workflow does not specify delimiters or explicit instructions to the agent to ignore embedded commands within email bodies. 3. Capability inventory: The skill has access to the email_send and text_summarize tools. 4. Sanitization: There is no evidence of filtering or validation of the ingested email content.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 12:08 PM
Security Audit — agent-trust-hub — email-digest