communication-systems

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements systems that ingest and process potentially untrusted external data for communications, which represents an indirect prompt injection surface.
  • Ingestion points: Untrusted data enters the system through options.data in the sendEmail function, payload in the sendPush function, and the payload argument in the sendWebhook function within SKILL.md.
  • Boundary markers: There are no explicit boundary markers or instructions to the model to ignore instructions embedded within the notification content or template data.
  • Capability inventory: The skill has the capability to perform network operations (sending emails via Resend, push notifications via FCM/WebPush, and webhooks via fetch) and write to a database via Prisma.
  • Sanitization: While the code uses standard serialization for JSON payloads, it lacks explicit HTML sanitization or validation for content interpolated into React Email templates, allowing for potential content injection if the source data is attacker-controlled.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:21 AM
Security Audit — agent-trust-hub — communication-systems