email-ops

Pass

Audited by Gen Agent Trust Hub on Apr 14, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data in the form of email threads.\n
  • Ingestion points: Mailbox threads are read from the mail surface during the "Read the thread before composing" step in SKILL.md.\n
  • Boundary markers: The instructions do not define delimiters or specific "ignore embedded instructions" warnings for the ingested email content.\n
  • Capability inventory: The agent has the capability to draft and live-send emails as described in SKILL.md, which could be exploited via malicious instructions in threads.\n
  • Sanitization: There is no requirement or instruction for sanitizing, validating, or escaping the content of the email threads before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 14, 2026, 12:20 AM
Security Audit — agent-trust-hub — email-ops