sinch-mailgun-validate

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data via bulk email lists (CSVs), which creates an ingestion surface for potential indirect prompt injection attacks where malicious instructions could be embedded in user-uploaded content.
  • Ingestion points: User-provided CSV files processed by the Bulk Validation API endpoints described in SKILL.md.
  • Boundary markers: The 'Security' section explicitly warns the agent to treat downloaded validation results as untrusted content.
  • Capability inventory: The skill facilitates network operations to the Mailgun API and document fetching from trusted documentation sites.
  • Sanitization: Instructions mandate that the agent validate and sanitize email addresses and metadata before processing or storage to mitigate risks from untrusted user content.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch authoritative technical documentation and API schemas from official vendor domains.
  • Evidence: Network requests and documentation links targeting documentation.mailgun.com and developers.sinch.com.
  • [SAFE]: The skill includes robust security guidance for handling API keys, recommending environment variables over hardcoding, and emphasizes PII protection for email lists.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:41 PM
Security Audit — agent-trust-hub — sinch-mailgun-validate