sales-newmail

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill implements a persistent memory mechanism via references/learnings.md, which is used to store and retrieve user-influenced tips and gotchas.\n
  • Ingestion points: references/learnings.md is read during Step 1 of the skill workflow in SKILL.md.\n
  • Boundary markers: The skill lacks explicit delimiters or instructions to the agent to disregard instructions potentially embedded within the 'learnings' file.\n
  • Capability inventory: The skill does not contain standalone scripts or direct command execution (subprocesses, eval, etc.), classifying it primarily as a set of instructions (NO_CODE).\n
  • Sanitization: There is no logic to sanitize or validate the content being written to or read from the learning store.\n- [NO_CODE]: The skill consists entirely of Markdown instructions and reference documents. No executable scripts (Python, JavaScript, shell) are included in the package.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 08:25 AM
Security Audit — agent-trust-hub — sales-newmail