email-triage-actions
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted email data that could contain malicious instructions aimed at influencing the agent's behavior during triage.
- Ingestion points: Local email content is ingested via the daily digest tool as specified in the Workflow section of SKILL.md.
- Boundary markers: The skill enforces mandatory human-in-the-loop confirmation for every execution plan and provides itemized review for local staging.
- Capability inventory: Operations are limited to read, archive, flag, and move actions, plus text-only draft generation; the skill explicitly excludes email-sending tools and provider-side deletion capabilities.
- Sanitization: Validation instructions require the agent to verify generated draft text for invented commitments, dates, or recipients before returning it to the user.
Audit Metadata