email-checkin

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted email data which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: SKILL.md (Workflow Step 3 and 4) uses mcp__intentmail__mail_sync and mcp__intentmail__mail_daily_digest to fetch external message content into the local cache.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the workflow to separate email content from agent instructions.
  • Capability inventory: The skill utilizes mcp__intentmail__mail_triage and mcp__intentmail__mail_summarize (SKILL.md) to analyze message content. The scope is restricted to read-only operations within this skill.
  • Sanitization: The provided instructions do not specify any validation or sanitization of the email content before it is processed by the AI models.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 02:11 PM
Security Audit — agent-trust-hub — email-checkin