twin-inbox-partner
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted external data in the form of inbox messages, which presents a surface for indirect prompt injection attacks.
- Ingestion points: The agent is instructed in
SKILL.mdto triage and draft replies based on messages from the user's inbox. - Boundary markers: Absent; there are no instructions to use delimiters or specifically ignore instructions that may be embedded within the processed email content.
- Capability inventory: No tool definitions or scripts are provided in the skill files; the agent's capabilities are limited to analyzing text and generating drafts.
- Sanitization: There is no mention of sanitizing, filtering, or validating the content of the incoming messages before they are processed by the agent.
Audit Metadata