postmark-automation

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the configuration of an external MCP server endpoint at https://rube.app/mcp. This is the primary service provider for the tools used in the skill and is required for its core functionality.
  • [SAFE]: No evidence of prompt injection, data exfiltration, or unauthorized command execution was found. The skill utilizes tool-based interactions through the Model Context Protocol (MCP) to interact with the Postmark API.
  • [SAFE]: While the skill processes potentially untrusted data through email templates and message bodies (representing a theoretical surface for indirect prompt injection), it follows standard operational procedures for transactional email management and lacks any specific patterns of exploitation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 04:27 AM
Security Audit — agent-trust-hub — postmark-automation