sales-proton-mail

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill implements a persistent knowledge-gathering loop through the use of references/learnings.md. It reads this file at startup and appends new observations to it during execution, creating an indirect prompt injection surface. \n
  • Ingestion points: references/learnings.md is read into the context during Step 1. \n
  • Boundary markers: No delimiters or instructions are used to differentiate learned content from system instructions. \n
  • Capability inventory: The skill can read local platform guides and recommend the installation of other tools via npx commands. \n
  • Sanitization: There is no validation or filtering of the content written to the learnings file. \n- [SAFE]: The documentation contains Python recipes for interacting with the Proton Mail Bridge using standard libraries. These are provided as educational examples and are not executed by the agent automatically. \n- [EXTERNAL_DOWNLOADS]: The skill mentions installation commands for related tools within the sales-skills organization. These are vendor-provided resources used for standard skill extensions and do not present a security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 08:25 AM
Security Audit — agent-trust-hub — sales-proton-mail