testing-with-sandbox
Pass
Audited by Gen Agent Trust Hub on Apr 9, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill is a documentation-only resource providing instructions on using Mailtrap's sandbox environment. It does not include any scripts, tools, or executable commands.
- [EXTERNAL_DOWNLOADS]: The skill references several official SDK repositories on GitHub (railsware/mailtrap-nodejs, railsware/mailtrap-python, etc.) and official documentation domains (mailtrap.io, docs.mailtrap.io). All external references are to the vendor's own verified infrastructure or well-known development resources.
- [DATA_EXFILTRATION]: No sensitive data exposure patterns were detected. API token examples use standard placeholders (e.g., YOUR_SANDBOX_API_TOKEN), and endpoints are limited to the official Mailtrap testing environment.
- [PROMPT_INJECTION]: No patterns associated with prompt injection, safety bypasses, or instruction overrides were found. The instructional tone is standard for technical documentation.
- [INDIRECT_PROMPT_INJECTION]: While the skill instructs the agent on how to retrieve email messages from a sandbox (which may contain untrusted data), it does not provide code for processing this data. The ingestion surface is the Mailtrap API (SKILL.md), and standard agent guardrails apply to the processing of the retrieved content.
Audit Metadata