agent-mail
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates inter-agent communication, creating a surface for indirect prompt injection. An agent processing the 'inbox' or 'thread' content might inadvertently execute instructions embedded within the message bodies sent by other agents.
- Ingestion points: Untrusted data enters the agent context through the
/api/mail/inbox,/api/mail/search, and/api/mail/thread/{id}/summaryendpoints as defined inSKILL.md. - Boundary markers: The instructions lack specific boundary markers or requirements for agents to treat the 'body_md' content as untrusted data.
- Capability inventory: The skill enables network operations (via
curl) and identifies local file paths ('project_path'). The agent using this skill likely has additional capabilities such as file modification and command execution. - Sanitization: There are no instructions for sanitizing, escaping, or validating the markdown content received from other agents before it is integrated into the current agent's context.
Audit Metadata