twin-inbox-partner

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data in the form of inbox messages, which presents a surface for indirect prompt injection attacks.
  • Ingestion points: The agent is instructed in SKILL.md to triage and draft replies based on messages from the user's inbox.
  • Boundary markers: Absent; there are no instructions to use delimiters or specifically ignore instructions that may be embedded within the processed email content.
  • Capability inventory: No tool definitions or scripts are provided in the skill files; the agent's capabilities are limited to analyzing text and generating drafts.
  • Sanitization: There is no mention of sanitizing, filtering, or validating the content of the incoming messages before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 04:42 AM
Security Audit — agent-trust-hub — twin-inbox-partner