connector-googlemail
Fail
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references libraries from the MOPS package registry (mops.one). Although flagged by automated scanners, these are the standard and expected sources for Motoko dependencies.
- [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection through the ingestion of user-controlled strings for email creation.
- Ingestion points: Data enters via the
to,subject, andbodyparameters in thesendEmailfunction insrc/backend/lib/gmail.mo. - Boundary markers: There are no explicit delimiters defined to isolate user input within the generated email body.
- Capability inventory: The skill uses the
gmail_users_messages_sendfunction to perform network outcalls to the Gmail API. - Sanitization: Content is encoded as UTF-8, but no specific semantic sanitization is applied to the input values.
- [COMMAND_EXECUTION]: The documentation includes shell commands for the
mopspackage manager to configure the backend environment.
Recommendations
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata