Back to skill

Security audit

Inbox Placement Monitor

Security checks for vulnerabilities and agentic risk

Overview

This skill is a focused email deliverability reporting helper with disclosed, user-controlled inputs and optional memory saving.

Install if you are comfortable providing email placement and reputation exports to the agent and optionally saving trend snapshots for later comparisons. Keep seed-send automation in dry-run unless you intentionally want live test emails sent to seed inboxes.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
## Save Results

After delivering, ask "Save these results for future sessions?" If yes, write the placement + reputation-trend report and the reusable SEND-`S` placement snapshot to `memory/email/inbox-placement-monitor/YYYY-MM-DD-<domain-or-topic>.md` — see [skill-contract.md §Save Results Template](../../../references/skill-contract.md). Store the current run's placement so it becomes the next run's baseline. Promote placement regressions and the current snapshot to `memory/hot-cache.md` and add unresolved regressions to `memory/open-loops.md`. Do not write memory without asking.

## Reference Materials
Confidence
75% confidence
Finding
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Static analysis

No suspicious patterns detected.