communication-systems
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements systems that ingest and process potentially untrusted external data for communications, which represents an indirect prompt injection surface.
- Ingestion points: Untrusted data enters the system through
options.datain thesendEmailfunction,payloadin thesendPushfunction, and thepayloadargument in thesendWebhookfunction withinSKILL.md. - Boundary markers: There are no explicit boundary markers or instructions to the model to ignore instructions embedded within the notification content or template data.
- Capability inventory: The skill has the capability to perform network operations (sending emails via Resend, push notifications via FCM/WebPush, and webhooks via
fetch) and write to a database via Prisma. - Sanitization: While the code uses standard serialization for JSON payloads, it lacks explicit HTML sanitization or validation for content interpolated into React Email templates, allowing for potential content injection if the source data is attacker-controlled.
Audit Metadata