sales-safetymails
Pass
Audited by Gen Agent Trust Hub on Apr 17, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill utilizes
references/learnings.mdto persist information across sessions, creating a surface for indirect prompt injection. \n - Ingestion points:
references/learnings.mdis read at the start of the interaction. \n - Boundary markers: Not present; the agent is not instructed to distinguish between system instructions and learned content. \n
- Capability inventory: The agent is instructed to write to
references/learnings.md. No scripts or automated execution capabilities are included. \n - Sanitization: No sanitization logic is provided for data written to the learnings file.\n- [EXTERNAL_DOWNLOADS]: The skill identifies the SafetyMails GitHub organization and suggests the use of
npxto install related skills. These are documented neutrally as they relate to the skill's primary function and author.
Audit Metadata