sinch-mailgun-inspect

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied HTML and link arrays for email quality analysis, constituting a potential attack surface. However, the skill provides specific mitigations. \n
  • Ingestion points: Ingestion occurs via the html field in accessibility, code analysis, and HTML validation endpoints, as well as the links URL array in link and image validation tasks. \n
  • Boundary markers: The agent is instructed to establish clear scope and configuration parameters (input method, region, language) before data processing. \n
  • Capability inventory: The skill uses curl for network requests to the api.mailgun.net and api.eu.mailgun.net API endpoints. \n
  • Sanitization: The 'Security' section provides explicit instructions to sanitize user-supplied content before submission to prevent malicious payloads. \n- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch authoritative documentation from trusted vendor domains. \n
  • Evidence: References to documentation.mailgun.com and developers.sinch.com are used for verifying API schemas and enums. \n- [COMMAND_EXECUTION]: The instructions provide canonical patterns for interacting with the REST API using shell tools. \n
  • Evidence: Examples include the use of curl for POST and GET requests and jq for parsing JSON responses. \n- [SAFE]: The skill implements strong security practices for credential handling. \n
  • Evidence: The skill explicitly advises against hardcoding API keys and recommends the use of environment variables or secret managers for the MAILGUN_API_KEY.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 01:06 PM
Security Audit — agent-trust-hub — sinch-mailgun-inspect