email-project-context

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from a local context/projects.md file to design and create email rules, which represents an indirect prompt injection surface.
  • Ingestion points: The Read tool is used to access the context/projects.md file in the working directory.
  • Boundary markers: The prompt does not specify the use of clear delimiters or instructions to ignore embedded commands within the ingested project context file.
  • Capability inventory: The skill possesses the ability to create, apply, and delete email rules via the mcp__intentmail__mail_create_rule, mcp__intentmail__mail_apply_rule, and mcp__intentmail__mail_delete_rule tools.
  • Sanitization: The risk is mitigated by explicit instructions to adhere to a strict rule schema (references/rule-contract.md), the use of dry-run modes to preview actions, and a mandatory workflow requiring user confirmation before any permanent changes are made.
  • [EXTERNAL_DOWNLOADS]: The skill relies on external software components and specific runtime environments to operate.
  • Evidence: The skill requires the installation and configuration of the IntentMail plugin and Node.js version 20 or newer.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 02:11 PM
Security Audit — agent-trust-hub — email-project-context