cold-email

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: A thorough audit of the skill instructions and its five reference files (benchmarks.md, follow-up-sequences.md, frameworks.md, personalization.md, and subject-lines.md) confirms the content is limited to professional copywriting advice. No indicators of obfuscation, persistence mechanisms, or unauthorized privilege escalation were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input and local context files to generate emails. * Ingestion points: Discovery questions in SKILL.md and the .agents/product-marketing-context.md file. * Boundary markers: None present. * Capability inventory: The skill is restricted to text generation; it performs no network requests, file writes, or command executions across any of its scripts or instructions. * Sanitization: No explicit filtering of input is implemented. Because the agent lacks active capabilities to interact with the system or network, the risk of injection is neutralized, potentially only influencing the content of the generated email copy.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 12:27 PM
Security Audit — agent-trust-hub — cold-email