email-checkin
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted email data which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points:
SKILL.md(Workflow Step 3 and 4) usesmcp__intentmail__mail_syncandmcp__intentmail__mail_daily_digestto fetch external message content into the local cache. - Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the workflow to separate email content from agent instructions.
- Capability inventory: The skill utilizes
mcp__intentmail__mail_triageandmcp__intentmail__mail_summarize(SKILL.md) to analyze message content. The scope is restricted to read-only operations within this skill. - Sanitization: The provided instructions do not specify any validation or sanitization of the email content before it is processed by the AI models.
Audit Metadata