pp-agentmail

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted email content from the AgentMail API, which could contain malicious instructions. * Ingestion points: Email subjects and bodies are ingested via threads search, triage queue, and thread rollup commands. * Boundary markers: No specific boundary markers or 'ignore' instructions are provided to delimit untrusted email content from agent instructions. * Capability inventory: The agent can execute bash commands and utilize the agentmail-pp-cli for network and file system operations. * Sanitization: The CLI outputs JSON data, but the agent parses and potentially acts upon instructions embedded within the email text.
  • [DYNAMIC_EXECUTION]: The CLI implements a 'Learning Loop' where it auto-synthesizes and re-executes 'playbooks' (command sequences) stored in a local SQLite database and JSON files. This dynamic execution of stored logic can be a vector for persistent influence if the agent is induced to 'teach' malicious patterns.
  • [DATA_EXFILTRATION]: The CLI includes a --deliver webhook:<url> feature that POSTs command results to a user-specified URL. While a core feature, it provides a direct mechanism for the agent to exfiltrate sensitive command output to external endpoints.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of binary tools from the vendor's GitHub repository (github.com/mvanhorn/printing-press-library) and NPM registry (@mvanhorn/printing-press-library).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:32 PM
Security Audit — agent-trust-hub — pp-agentmail