gmail-attachments
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted email data (ingestion points in
SKILL.mdandreferences/contract.md). It implements comprehensive security mitigations to prevent injection attacks: - Mandatory boundary markers: All sender-controlled content (filenames, subjects, body text) is wrapped in
<untrusted-content>envelopes. - Non-execution instructions: The agent is explicitly forbidden from opening, executing, or summarizing downloaded files, or treating their contents as instructions.
- Data sanitization: The skill identifies risk flags (executables, scripts, macros) and reports them to the user before any action is taken.
- [DATA_EXFILTRATION]: A robust "jail" mechanism (detailed in
references/jail.md) prevents the agent from attaching sensitive local files. It explicitly denies access to SSH keys (~/.ssh), cloud credentials (~/.aws), environment files (.env), and repository internals (.git), even if the agent attempts to bypass checks using symlinks. - [OBFUSCATION]: The documentation in
SKILL.mdcontains a Right-to-Left Override character (U+202E) in the example stringinvoicefdp.exe. This is used as an educational example to demonstrate how the skill detects and strips such characters during filename sanitization to prevent spoofing. - [COMMAND_EXECUTION]: The skill interacts with the filesystem and the
agent-gmailCLI tool but enforces strict human-in-the-loop requirements. Downloads only occur after a user selects a destination from a generated question, and attachments are restricted to user-defined allowed roots. - [SAFE]: Filename sanitization automatically renames potentially dangerous files (like
.exeor.pth) with a.downloadextension, ensuring they cannot be accidentally executed by the operating system or build tools.
Audit Metadata