email-triage-actions

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted email data that could contain malicious instructions aimed at influencing the agent's behavior during triage.
  • Ingestion points: Local email content is ingested via the daily digest tool as specified in the Workflow section of SKILL.md.
  • Boundary markers: The skill enforces mandatory human-in-the-loop confirmation for every execution plan and provides itemized review for local staging.
  • Capability inventory: Operations are limited to read, archive, flag, and move actions, plus text-only draft generation; the skill explicitly excludes email-sending tools and provider-side deletion capabilities.
  • Sanitization: Validation instructions require the agent to verify generated draft text for invented commitments, dates, or recipients before returning it to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 02:11 PM
Security Audit — agent-trust-hub — email-triage-actions