swoosh-emails

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides standard documentation and templates for implementing Swoosh emails in Phoenix applications.
  • [CREDENTIALS_UNSAFE]: The skill correctly instructs the user to use System.get_env("SENDGRID_API_KEY") in config/runtime.exs rather than hardcoding credentials, which is a secure practice.
  • [COMMAND_EXECUTION]: There are no shell command executions or dynamic code generation patterns. The !command syntax was not detected.
  • [DATA_EXFILTRATION]: No network operations to unknown or suspicious domains were found. The use of SendGrid is documented as a standard production adapter choice.
  • [PROMPT_INJECTION]: No instructional overrides, DAN patterns, or bypass techniques were detected in the markdown or code comments.
  • [INDIRECT_PROMPT_INJECTION]: While the skill handles user data (name/email) for interpolation into templates, it uses Phoenix components and standard Elixir string interpolation, which does not present a specific vulnerability surface for the agent analyzer context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 12:24 AM
Security Audit — agent-trust-hub — swoosh-emails