email-notifications
Pass
Audited by Gen Agent Trust Hub on Aug 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: Technical Documentation
- The skill serves as a legitimate reference for ServiceNow developers, covering notification components such as templates, events, and email scripts.
- [SAFE]: Code Integrity
- JavaScript examples provided are standard ServiceNow Rhino engine (ES5) scripts and utilize legitimate GlideRecord APIs for data retrieval and template generation within the platform context.
- [SAFE]: Data Handling
- No hardcoded credentials, sensitive file access, or unauthorized network operations were identified. Configuration examples reference standard system property keys without exposing actual secrets.
- [SAFE]: Indirect Prompt Injection Surface
- Although the skill demonstrates interpolating incident fields (like description) into notifications, this is a standard platform feature for its primary purpose. No patterns were found instructing the agent to execute untrusted data or override safety guidelines.
Audit Metadata