connector-googlemail

Fail

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references libraries from the MOPS package registry (mops.one). Although flagged by automated scanners, these are the standard and expected sources for Motoko dependencies.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection through the ingestion of user-controlled strings for email creation.
  • Ingestion points: Data enters via the to, subject, and body parameters in the sendEmail function in src/backend/lib/gmail.mo.
  • Boundary markers: There are no explicit delimiters defined to isolate user input within the generated email body.
  • Capability inventory: The skill uses the gmail_users_messages_send function to perform network outcalls to the Gmail API.
  • Sanitization: Content is encoded as UTF-8, but no specific semantic sanitization is applied to the input values.
  • [COMMAND_EXECUTION]: The documentation includes shell commands for the mops package manager to configure the backend environment.
Recommendations
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 22, 2026, 02:12 PM
Security Audit — agent-trust-hub — connector-googlemail