email-notifications

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: Technical Documentation
  • The skill serves as a legitimate reference for ServiceNow developers, covering notification components such as templates, events, and email scripts.
  • [SAFE]: Code Integrity
  • JavaScript examples provided are standard ServiceNow Rhino engine (ES5) scripts and utilize legitimate GlideRecord APIs for data retrieval and template generation within the platform context.
  • [SAFE]: Data Handling
  • No hardcoded credentials, sensitive file access, or unauthorized network operations were identified. Configuration examples reference standard system property keys without exposing actual secrets.
  • [SAFE]: Indirect Prompt Injection Surface
  • Although the skill demonstrates interpolating incident fields (like description) into notifications, this is a standard platform feature for its primary purpose. No patterns were found instructing the agent to execute untrusted data or override safety guidelines.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 11:30 PM
Security Audit — agent-trust-hub — email-notifications