agent-postmark

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a dedicated CLI tool 'agent-postmark' for interacting with Postmark services. All execution is limited to this tool's predefined interface.- [DATA_EXFILTRATION]: The skill documentation mandates that sensitive tokens are never shared in chat and must be handled via local secure OS dialogs. The tool also implements automatic redaction for secrets and private email content to prevent accidental exposure.- [PROMPT_INJECTION]: The skill ingests untrusted data from email messages. This indirect prompt injection surface is mitigated by strict redaction of sensitive fields and a requirement for manual user confirmation ('--yes') for all state-changing commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 01:20 PM
Security Audit — agent-trust-hub — agent-postmark