cold-email

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill instructions and associated README are focused strictly on the legitimate task of generating B2B email copy. The skill does not request or perform any network operations, file system modifications, or shell command executions.
  • [PROMPT_INJECTION]: The skill processes untrusted user data, including prospect information, sender details, and existing email drafts, which constitutes an indirect prompt injection surface. However, the risk is effectively mitigated by the skill's lack of high-privilege capabilities.
  • Ingestion points: User-provided text regarding prospect personas, company triggers, and draft email content processed in SKILL.md.
  • Boundary markers: Absent; the skill does not explicitly instruct the agent to ignore or delimit instructions contained within user-supplied variables.
  • Capability inventory: The skill's scope is restricted to text generation for email copywriting; it does not utilize tools for network access, file writing, or system command execution.
  • Sanitization: No explicit sanitization or input validation rules are provided for handling interpolated user data.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 08:05 PM
Security Audit — agent-trust-hub — cold-email