agent-mail

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates inter-agent communication, creating a surface for indirect prompt injection. An agent processing the 'inbox' or 'thread' content might inadvertently execute instructions embedded within the message bodies sent by other agents.
  • Ingestion points: Untrusted data enters the agent context through the /api/mail/inbox, /api/mail/search, and /api/mail/thread/{id}/summary endpoints as defined in SKILL.md.
  • Boundary markers: The instructions lack specific boundary markers or requirements for agents to treat the 'body_md' content as untrusted data.
  • Capability inventory: The skill enables network operations (via curl) and identifies local file paths ('project_path'). The agent using this skill likely has additional capabilities such as file modification and command execution.
  • Sanitization: There are no instructions for sanitizing, escaping, or validating the markdown content received from other agents before it is integrated into the current agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 08:25 PM
Security Audit — agent-trust-hub — agent-mail