nylas-api
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill provides legitimate documentation and integration guidance for the Nylas v3 API. All referenced resources and packages are official vendor tools.
- [INDIRECT_PROMPT_INJECTION]: The skill identifies grant-scoped API data as an attack surface for indirect prompt injection. It mandates safety protocols such as treating external data as untrusted and requiring user confirmation for mutations. Ingestion points include messages, events, and contact data (rules/security-untrusted-content.md). Capabilities include sending emails and managing calendar resources. Sanitization is addressed via the message cleaning endpoint.
- [EXTERNAL_DOWNLOADS]: The skill references official Nylas SDKs for Node.js, Python, and Ruby, along with official documentation links. These originate from the verified vendor infrastructure.
Audit Metadata