sinch-mailgun-validate
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data via bulk email lists (CSVs), which creates an ingestion surface for potential indirect prompt injection attacks where malicious instructions could be embedded in user-uploaded content.
- Ingestion points: User-provided CSV files processed by the Bulk Validation API endpoints described in
SKILL.md. - Boundary markers: The 'Security' section explicitly warns the agent to treat downloaded validation results as untrusted content.
- Capability inventory: The skill facilitates network operations to the Mailgun API and document fetching from trusted documentation sites.
- Sanitization: Instructions mandate that the agent validate and sanitize email addresses and metadata before processing or storage to mitigate risks from untrusted user content.
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch authoritative technical documentation and API schemas from official vendor domains.
- Evidence: Network requests and documentation links targeting
documentation.mailgun.comanddevelopers.sinch.com. - [SAFE]: The skill includes robust security guidance for handling API keys, recommending environment variables over hardcoding, and emphasizes PII protection for email lists.
Audit Metadata