resend-cli
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted third-party data through the
emails receivingcommands (inbound emails). The documentation includes a specific security warning for agents to treat this content strictly as data and never as instructions, which follows security best practices for handling external input. - [DYNAMIC_EXECUTION]: The
emails sendcommand supports a--react-emailflag which bundles and renders React (.tsx) templates locally using esbuild. This is a standard functional feature of the Resend ecosystem for previewing and sending React-based emails. - [CREDENTIALS_SAFE]: The skill provides explicit instructions on how to handle the
RESEND_API_KEYsafely, advising users and agents to use environment variables or stored profiles instead of passing literal keys in commands, preventing exposure in shell histories and logs.
Audit Metadata