cloudflare-email-service
Pass
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data through the Cloudflare Email Routing service.
- Ingestion points: The
email()handler described inreferences/routing.mdaccepts raw MIME content (message.raw) from any external sender. - Boundary markers: The skill does not provide specific instructions for using delimiters or boundary markers when the agent processes the parsed email body.
- Capability inventory: The skill demonstrates capabilities for sending emails (
env.EMAIL.send()), forwarding content (message.forward()), and storing parsed data in Durable Objects for later retrieval by AI agents. - Sanitization: While the skill demonstrates parsing with
postal-mime, it does not prescribe sanitization of the resulting text/HTML before it is used to "trigger an AI agent to draft a reply". - Note: The skill explicitly advises best practices to mitigate this risk, such as "Never auto-send from the email() handler in a human-in-the-loop flow. Store a draft, let the user review, then send via a separate action."
Audit Metadata