sales-inbox-zero
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [SAFE]: Analysis of the skill instructions and references found no evidence of malicious behavior, data exfiltration, or obfuscation. The skill serves its stated purpose as a platform guide.
- [COMMAND_EXECUTION]: The skill provides examples of using the official Inbox Zero CLI and REST API via
curlandnpxto manage automation rules. These commands are informational and intended for user-approved workflows. - [EXTERNAL_DOWNLOADS]: The skill references the installation of official Node.js packages
@inbox-zero/apiand@inbox-zero/cli. These are the verified packages for the platform described. - [PROMPT_INJECTION]: The skill processes user instructions to define automation rules and updates a local knowledge base in
references/learnings.md. Mandatory Evidence Chain: 1. Ingestion points: User input in Step 1 and thereferences/learnings.mdfile. 2. Boundary markers: Absent. 3. Capability inventory: Network communication viacurlandnpx, and file modification capabilities. 4. Sanitization: Absent. This risk is assessed as low given the interactive and documentation-focused nature of the skill.
Audit Metadata