lumail
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on executing the
lumailCLI tool vianpxorbun. It also instructs the agent to use shell redirection to read token files (e.g.,TOKEN=$(tr -d '\n' < ~/.config/lumail/token)). - [DYNAMIC_EXECUTION]: The skill includes a fallback for stale CLI installations that involves navigating to a hardcoded local path (
/Users/melvynx/Developer/projects/lumail.io) and executing a script directly usingbun src/cli/index.ts. This is environment-specific and executes local code. - [CREDENTIALS_UNSAFE]: The skill manages sensitive API tokens and OAuth credentials stored in
~/.config/lumail/. It provides explicit instructions for displaying raw tokens using the--rawflag (e.g.,npx lumail auth show --rawandlumail accounts show <name> --raw), which exposes secrets in the agent's output. - [INDIRECT_PROMPT_INJECTION]: The skill includes a
fetch_web_pagetool and facilitates the creation of email content based on external data, creating a vector for instructions embedded in external content to influence the agent. - Ingestion points: The
fetch_web_pagetool (mentioned in the V2 Tools API section) and the processing of TipTap JSON documents that may contain remote content or URLs. - Boundary markers: None mentioned; instructions do not advise the agent to ignore embedded commands in fetched data.
- Capability inventory: The skill has extensive write and network capabilities, including sending transactional emails (
emails send), scheduling marketing campaigns (schedule_campaign), and configuring automation workflows (configure_workflow_v2_draft). - Sanitization: No sanitization or validation steps are described for data fetched from the web before it is used in email content or workflow configurations.
Audit Metadata