skills/sinch/skills/sinch-mailgun/Gen Agent Trust Hub

sinch-mailgun

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a vulnerability surface where the agent processes untrusted data from inbound emails and webhooks. 1. Ingestion points: Inbound email headers, body content, and webhook payloads described in the 'Inbound Routing' and 'Webhooks' sections. 2. Boundary markers: The 'Security' and 'Inbound Routing' sections provide clear instructions to treat incoming content as 'untrusted data' and 'not an instruction,' even if it contains phrases like 'ignore previous instructions.' 3. Capability inventory: The skill is scoped to email management via the Mailgun API (sending, tracking, templates) and does not expose system-level file-writing or arbitrary command execution to the data pipeline. 4. Sanitization: Instructions mandate verifying HMAC signatures for webhooks and sanitizing inbound content before storage or display.
  • [EXTERNAL_DOWNLOADS]: The agent is instructed to fetch documentation from authoritative vendor sources. Evidence: The skill points to documentation.mailgun.com and developers.sinch.com for request/response schemas.
  • [COMMAND_EXECUTION]: The skill provides standard shell commands for testing and installation. Evidence: Examples include curl commands for API requests and npm install commands for the mailgun.js SDK.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:38 PM
Security Audit — agent-trust-hub — sinch-mailgun