skills/magentosh/skills/email-design/Gen Agent Trust Hub

email-design

Fail

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill uses npx to install a third-party package (belt-sh/cli) and utilizes the belt app run command to execute remote logic for HTML-to-image conversion and AI image generation.
  • [EXTERNAL_DOWNLOADS]: The skill fetches content and installation guidelines from an external GitHub repository (inference-sh/skills).
  • [PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection by passing user-influenced HTML strings directly into remote rendering tools without visible sanitization or boundary markers.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 23, 2026, 06:03 PM
Security Audit — agent-trust-hub — email-design