event-attendee-email-sequences

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a set of guidelines and instructions for generating email content based on event planning data. It adheres to privacy best practices, such as distinguishing transaction consent from marketing consent and requiring human review of generated content.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from multiple ingestion points (user interviews and sibling skills) to generate email drafts. While this involves processing untrusted data, the skill lacks high-risk capabilities and includes safety constraints.
  • Ingestion points: User-provided interview answers (SKILL.md) and data inputs from associated vendor-owned skills covering marketing plans, ticket pricing, and attendee experience.
  • Boundary markers: The skill defines strict ownership boundaries, routing specific problems (like no-show management or code of conduct) to dedicated sibling skills.
  • Capability inventory: The skill is limited to text generation for emails and does not possess capabilities for command execution, unauthorized network access, or file system modification.
  • Sanitization: It includes a mandatory humanizer pass (workflow step 9) and list hygiene checks (workflow step 10) before any content is finalized or sent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:13 PM
Security Audit — agent-trust-hub — event-attendee-email-sequences