react-email
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The documentation references standard installation procedures for the
react-emaillibrary and its components via NPM. It also suggests adding theresendskill from the same author (oakoss) using the platform's standard command. - [INDIRECT_PROMPT_INJECTION]: The skill describes a templating engine that interpolates dynamic data into emails (e.g.,
{name},{orderId}). - Ingestion points: Component props in React templates documented in
references/components.mdandreferences/rendering.md. - Boundary markers: React's JSX engine provides default escaping for strings to prevent script injection.
- Capability inventory: The skill focuses on generating HTML strings for email delivery via third-party providers (Resend, Nodemailer, SendGrid, AWS SES).
- Sanitization: Standard React component architecture handles variable interpolation safely.
- [COMMAND_EXECUTION]: Provides instructions for using the
email devandemail exportCLI tools provided by the React Email library for local development and static generation. - [CREDENTIALS_SAFE]: Code examples demonstrate correct security practices by using environment variables (
process.env.RESEND_API_KEY,process.env.SMTP_PASS) for API keys and SMTP credentials instead of hardcoding sensitive information.
Audit Metadata