sequenzy-email-marketing

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides operational guidance for a specific email marketing platform ('Sequenzy'). All external domains referenced (sequenzy.com, api.sequenzy.com, sequenzydns.com) are official vendor resources belonging to the skill's author. The skill includes specific security best practices, such as advising against pasting raw secret values into the chat and recommending the use of local .env files for credential management.
  • [INDIRECT_PROMPT_INJECTION]: The skill handles untrusted data from external sources, such as subscriber profiles (emails, names, custom attributes) and campaign content. This presents a potential surface for indirect prompt injection attacks.
  • Ingestion points: Subscriber data is ingested via bulk imports (CSV, JSON) and API updates as described in references/command-reference.md.
  • Boundary markers: The skill explicitly instructs the agent to validate all recipient details and content inputs before executing mutations.
  • Capability inventory: The skill enables the agent to send emails, manage marketing campaigns, and interact with the Sequenzy API to modify account resources.
  • Sanitization: The instructions mandate that all AI-generated content be treated as draft material requiring review, and specifically warn against the exposure of sensitive credentials like API keys.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 12:26 PM
Security Audit — agent-trust-hub — sequenzy-email-marketing