check-inbox

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted data from external sources (emails and Slack), creating a surface for Indirect Prompt Injection.
  • Ingestion points: Content is ingested from Markdown files in /output/gmail/ and slack-sync/data/ via scripts/email_parser.py and scripts/slack_parser.py.
  • Boundary markers: scripts/llm_analyzer.py wraps all external content in <external_untrusted_content> boundary tags and provides explicit system instructions to the LLM to ignore any directives within those tags.
  • Capability inventory: The skill has no file-write capabilities for untrusted data and no shell execution of external strings. Capabilities are limited to generating a text summary and sending notifications via the LINE Messaging API.
  • Sanitization: scripts/llm_analyzer.py includes a sanitize_external_text function that proactively removes boundary tags from user input (preventing delimiter escaping) and strips hidden Unicode characters used for visual obfuscation.
  • [PROMPT_INJECTION]: Static analysis identified the phrase 'ignore previous instructions' in SKILL.en.md. Manual review confirms this is part of a security advisory warning the user about potential attacks, not an attempt to hijack the agent's behavior.
  • [SAFE]: Credentials for Gemini and LINE are managed through environment variables and a credential manager. No hardcoded secrets were found.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 05:59 AM
Security Audit — agent-trust-hub — check-inbox