sales-proton-mail
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill implements a persistent knowledge-gathering loop through the use of references/learnings.md. It reads this file at startup and appends new observations to it during execution, creating an indirect prompt injection surface. \n
- Ingestion points: references/learnings.md is read into the context during Step 1. \n
- Boundary markers: No delimiters or instructions are used to differentiate learned content from system instructions. \n
- Capability inventory: The skill can read local platform guides and recommend the installation of other tools via npx commands. \n
- Sanitization: There is no validation or filtering of the content written to the learnings file. \n- [SAFE]: The documentation contains Python recipes for interacting with the Proton Mail Bridge using standard libraries. These are provided as educational examples and are not executed by the agent automatically. \n- [EXTERNAL_DOWNLOADS]: The skill mentions installation commands for related tools within the sales-skills organization. These are vendor-provided resources used for standard skill extensions and do not present a security risk.
Audit Metadata