email-agent-preflight

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill references phrases typical of prompt injections, such as "admin mode" and "ignore your previous instructions," but uses them as negative examples for the agent to watch for in external data. It does not attempt to override the agent's core instructions or bypass safety filters.
  • [INDIRECT_PROMPT_INJECTION]: The content specifically addresses the threat surface of indirect prompt injection in email bodies. It provides a defensive strategy for agents to treat ingested content as untrusted data and includes a "tell-list" of suspicious patterns to identify malicious instructions, serving as a mitigation guide rather than a vulnerability.
  • [PRIVILEGE_ESCALATION]: The instructions explicitly advocate for the principle of least privilege by defining tiered access levels (read, draft, approve-send, auto-send) and warning against granting higher permissions without human-in-the-loop controls.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 05:57 PM
Security Audit — agent-trust-hub — email-agent-preflight