email-drafter
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the user's email history to perform tone analysis.
- Ingestion points: The skill retrieves 3–5 recent sent emails via the WorkIQ tool (
SKILL.md). - Boundary markers: There are no explicit delimiters or instructions provided to the agent to disregard potential commands embedded within the retrieved email content.
- Capability inventory: The skill allows writing generated content to markdown files within the
outputs/directory (SKILL.md). - Sanitization: No specific sanitization or filtering logic is mentioned for the ingested email data before it is used to influence the agent's drafting behavior.
- Note: The risk is mitigated by explicit instructions to never send emails automatically and a mandate to respect privacy by excluding unrelated sensitive information.
Audit Metadata