pp-agentmail
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted email content from the AgentMail API, which could contain malicious instructions. * Ingestion points: Email subjects and bodies are ingested via
threads search,triage queue, andthread rollupcommands. * Boundary markers: No specific boundary markers or 'ignore' instructions are provided to delimit untrusted email content from agent instructions. * Capability inventory: The agent can execute bash commands and utilize theagentmail-pp-clifor network and file system operations. * Sanitization: The CLI outputs JSON data, but the agent parses and potentially acts upon instructions embedded within the email text. - [DYNAMIC_EXECUTION]: The CLI implements a 'Learning Loop' where it auto-synthesizes and re-executes 'playbooks' (command sequences) stored in a local SQLite database and JSON files. This dynamic execution of stored logic can be a vector for persistent influence if the agent is induced to 'teach' malicious patterns.
- [DATA_EXFILTRATION]: The CLI includes a
--deliver webhook:<url>feature that POSTs command results to a user-specified URL. While a core feature, it provides a direct mechanism for the agent to exfiltrate sensitive command output to external endpoints. - [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of binary tools from the vendor's GitHub repository (
github.com/mvanhorn/printing-press-library) and NPM registry (@mvanhorn/printing-press-library).
Audit Metadata