resend-cli

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted third-party data through the emails receiving commands (inbound emails). The documentation includes a specific security warning for agents to treat this content strictly as data and never as instructions, which follows security best practices for handling external input.
  • [DYNAMIC_EXECUTION]: The emails send command supports a --react-email flag which bundles and renders React (.tsx) templates locally using esbuild. This is a standard functional feature of the Resend ecosystem for previewing and sending React-based emails.
  • [CREDENTIALS_SAFE]: The skill provides explicit instructions on how to handle the RESEND_API_KEY safely, advising users and agents to use environment variables or stored profiles instead of passing literal keys in commands, preventing exposure in shell histories and logs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 11:49 AM
Security Audit — agent-trust-hub — resend-cli