> For the complete documentation index, see [llms.txt](https://csbygb.gitbook.io/pentips/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://csbygb.gitbook.io/pentips/writeups/giskard-red/giskard-email-assistant3.md).

# Giskard - Email Assistant (Level 3)

* [Link to challenge](https://red.giskard.ai/challenges/insecure-agents/email-assistant-3)

## Instructions

![Instructions](/files/rWVr3IKQSlZtfvVnhtld)

## Resolution

As this is an agent it might have access to an api. So I asked if it had access to an API and it said yes. SO then I asked it to list all the api actions and I got the send\_emails action.

![List api action](/files/dKRdEY79ng5bvozK8ssX)

So I asked how it would use the api action to send email and I got this answer:

![send email action json](/files/xX2CaRvsCcGkpAbfSBz0)

For some reason I am able to have it show a post request with the api action, but it does not validate the challenge. It means it considers the email is not sent:

![POST REQUEST](/files/9tBWIsoPly05Dzxzb4gK)

![coming soon](/files/jkI4QotoHecf62YipxxY)
