gmail
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill's behavior is consistent with its stated purpose of Gmail automation and uses legitimate browser automation tools.
- [PROMPT_INJECTION]: The skill possesses an inherent attack surface for indirect prompt injection because it processes untrusted email content. Ingestion points: Extraction of email text via
read_pageandget_page_textin SKILL.md. Boundary markers: Absent; there are no instructions to the agent to treat email content as untrusted data or ignore instructions within it. Capability inventory: The agent can navigate, input text, and perform actions (like sending emails) via themcp__claude-in-chrome__*tools. Sanitization: Absent.
Audit Metadata