skills/melvynx/lumail-skills/lumail/Gen Agent Trust Hub

lumail

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on executing the lumail CLI tool via npx or bun. It also instructs the agent to use shell redirection to read token files (e.g., TOKEN=$(tr -d '\n' < ~/.config/lumail/token)).
  • [DYNAMIC_EXECUTION]: The skill includes a fallback for stale CLI installations that involves navigating to a hardcoded local path (/Users/melvynx/Developer/projects/lumail.io) and executing a script directly using bun src/cli/index.ts. This is environment-specific and executes local code.
  • [CREDENTIALS_UNSAFE]: The skill manages sensitive API tokens and OAuth credentials stored in ~/.config/lumail/. It provides explicit instructions for displaying raw tokens using the --raw flag (e.g., npx lumail auth show --raw and lumail accounts show <name> --raw), which exposes secrets in the agent's output.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes a fetch_web_page tool and facilitates the creation of email content based on external data, creating a vector for instructions embedded in external content to influence the agent.
  • Ingestion points: The fetch_web_page tool (mentioned in the V2 Tools API section) and the processing of TipTap JSON documents that may contain remote content or URLs.
  • Boundary markers: None mentioned; instructions do not advise the agent to ignore embedded commands in fetched data.
  • Capability inventory: The skill has extensive write and network capabilities, including sending transactional emails (emails send), scheduling marketing campaigns (schedule_campaign), and configuring automation workflows (configure_workflow_v2_draft).
  • Sanitization: No sanitization or validation steps are described for data fetched from the web before it is used in email content or workflow configurations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 06:54 PM