sales-inbox-zero

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: Analysis of the skill instructions and references found no evidence of malicious behavior, data exfiltration, or obfuscation. The skill serves its stated purpose as a platform guide.
  • [COMMAND_EXECUTION]: The skill provides examples of using the official Inbox Zero CLI and REST API via curl and npx to manage automation rules. These commands are informational and intended for user-approved workflows.
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of official Node.js packages @inbox-zero/api and @inbox-zero/cli. These are the verified packages for the platform described.
  • [PROMPT_INJECTION]: The skill processes user instructions to define automation rules and updates a local knowledge base in references/learnings.md. Mandatory Evidence Chain: 1. Ingestion points: User input in Step 1 and the references/learnings.md file. 2. Boundary markers: Absent. 3. Capability inventory: Network communication via curl and npx, and file modification capabilities. 4. Sanitization: Absent. This risk is assessed as low given the interactive and documentation-focused nature of the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 08:30 AM
Security Audit — agent-trust-hub — sales-inbox-zero