react-email

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation references standard installation procedures for the react-email library and its components via NPM. It also suggests adding the resend skill from the same author (oakoss) using the platform's standard command.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a templating engine that interpolates dynamic data into emails (e.g., {name}, {orderId}).
  • Ingestion points: Component props in React templates documented in references/components.md and references/rendering.md.
  • Boundary markers: React's JSX engine provides default escaping for strings to prevent script injection.
  • Capability inventory: The skill focuses on generating HTML strings for email delivery via third-party providers (Resend, Nodemailer, SendGrid, AWS SES).
  • Sanitization: Standard React component architecture handles variable interpolation safely.
  • [COMMAND_EXECUTION]: Provides instructions for using the email dev and email export CLI tools provided by the React Email library for local development and static generation.
  • [CREDENTIALS_SAFE]: Code examples demonstrate correct security practices by using environment variables (process.env.RESEND_API_KEY, process.env.SMTP_PASS) for API keys and SMTP credentials instead of hardcoding sensitive information.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:51 AM
Security Audit — agent-trust-hub — react-email