inbox-processor

Pass

Audited by Gen Agent Trust Hub on May 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions create a vulnerability surface for indirect prompt injection by processing untrusted data.
  • Ingestion points: The skill reads all content from files located in the '00_Inbox/' directory.
  • Boundary markers: There are no instructions to use delimiters or specific ignore-rules for the content of the notes being analyzed.
  • Capability inventory: The skill generates an action plan for moving and deleting files, which could be exploited if an ingested note contains malicious instructions.
  • Sanitization: There is no evidence of sanitization, validation, or escaping of the content read from the inbox files.
Audit Metadata
Risk Level
SAFE
Analyzed
May 16, 2026, 10:07 AM
Security Audit — agent-trust-hub — inbox-processor