enhance-lifecycle-email

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface by recommending the ingestion of external product event signals to automate communications.
  • Ingestion points: Product signals such as signup_completed, setup_started, and activated as defined in the mapping section of SKILL.md.
  • Boundary markers: No specific delimiters or safety instructions are defined for processing untrusted event metadata.
  • Capability inventory: Triggers network-based email dispatch through providers like Resend, Postmark, and AWS SES.
  • Sanitization: The instructions do not detail sanitization or validation logic for the ingested data.
  • [NO_CODE]: This skill is entirely instructional and does not contain any scripts, binaries, or executable logic.
  • [SAFE]: The described logic, including idempotency, transactional classification, and consent management, aligns with industry best practices for automated lifecycle messaging.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 05:41 PM
Security Audit — agent-trust-hub — enhance-lifecycle-email