check-inbox
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted data from external sources (emails and Slack), creating a surface for Indirect Prompt Injection.
- Ingestion points: Content is ingested from Markdown files in
/output/gmail/andslack-sync/data/viascripts/email_parser.pyandscripts/slack_parser.py. - Boundary markers:
scripts/llm_analyzer.pywraps all external content in<external_untrusted_content>boundary tags and provides explicit system instructions to the LLM to ignore any directives within those tags. - Capability inventory: The skill has no file-write capabilities for untrusted data and no shell execution of external strings. Capabilities are limited to generating a text summary and sending notifications via the LINE Messaging API.
- Sanitization:
scripts/llm_analyzer.pyincludes asanitize_external_textfunction that proactively removes boundary tags from user input (preventing delimiter escaping) and strips hidden Unicode characters used for visual obfuscation. - [PROMPT_INJECTION]: Static analysis identified the phrase 'ignore previous instructions' in
SKILL.en.md. Manual review confirms this is part of a security advisory warning the user about potential attacks, not an attempt to hijack the agent's behavior. - [SAFE]: Credentials for Gemini and LINE are managed through environment variables and a credential manager. No hardcoded secrets were found.
Audit Metadata