sinch-mailgun-validate

Pass

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data in the form of email addresses and CSV files for validation. While this represents an attack surface, the skill includes explicit security instructions to treat downloaded content as untrusted and to sanitize data before processing, which aligns with security best practices.
  • [EXTERNAL_DOWNLOADS]: The skill references and provides installation instructions for official Mailgun SDKs across multiple languages (Node.js, Python, Java, PHP, Ruby, and Go). All links and packages point to official Mailgun and Sinch resources.
  • [CREDENTIALS_UNSAFE]: The skill correctly instructs users to store API keys in environment variables (MAILGUN_API_KEY) and explicitly warns against hardcoding credentials in source code or logs.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 15, 2026, 10:16 AM
Security Audit — agent-trust-hub — sinch-mailgun-validate