skills/craftos-dev/craftbot/gmail/Gen Agent Trust Hub

gmail

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: Credential Management: The skill utilizes the MATON_API_KEY environment variable for authentication, which is a secure practice that avoids hardcoding sensitive credentials.- [SAFE]: Network Activity: All network operations are directed to the vendor's official subdomains (gateway.maton.ai, ctrl.maton.ai) to facilitate the managed OAuth and Gmail proxy functionality.- [SAFE]: Code Safety: The skill provides static Python examples using the standard library for the agent to follow, with no evidence of remote code execution or unauthorized shell commands.- [SAFE]: Indirect Prompt Injection Surface: The skill reads external email data as part of its primary function. While this constitutes an attack surface, it is a standard feature of email integrations and the skill does not include instructions that would lead to unsafe processing of that data.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 12:14 AM
Security Audit — agent-trust-hub — gmail