email-ops
Pass
Audited by Gen Agent Trust Hub on Apr 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted external data in the form of email threads.\n
- Ingestion points: Mailbox threads are read from the mail surface during the "Read the thread before composing" step in SKILL.md.\n
- Boundary markers: The instructions do not define delimiters or specific "ignore embedded instructions" warnings for the ingested email content.\n
- Capability inventory: The agent has the capability to draft and live-send emails as described in SKILL.md, which could be exploited via malicious instructions in threads.\n
- Sanitization: There is no requirement or instruction for sanitizing, validating, or escaping the content of the email threads before processing.
Audit Metadata