gmail-attachments

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted email data (ingestion points in SKILL.md and references/contract.md). It implements comprehensive security mitigations to prevent injection attacks:
  • Mandatory boundary markers: All sender-controlled content (filenames, subjects, body text) is wrapped in <untrusted-content> envelopes.
  • Non-execution instructions: The agent is explicitly forbidden from opening, executing, or summarizing downloaded files, or treating their contents as instructions.
  • Data sanitization: The skill identifies risk flags (executables, scripts, macros) and reports them to the user before any action is taken.
  • [DATA_EXFILTRATION]: A robust "jail" mechanism (detailed in references/jail.md) prevents the agent from attaching sensitive local files. It explicitly denies access to SSH keys (~/.ssh), cloud credentials (~/.aws), environment files (.env), and repository internals (.git), even if the agent attempts to bypass checks using symlinks.
  • [OBFUSCATION]: The documentation in SKILL.md contains a Right-to-Left Override character (U+202E) in the example string invoice‮fdp.exe. This is used as an educational example to demonstrate how the skill detects and strips such characters during filename sanitization to prevent spoofing.
  • [COMMAND_EXECUTION]: The skill interacts with the filesystem and the agent-gmail CLI tool but enforces strict human-in-the-loop requirements. Downloads only occur after a user selects a destination from a generated question, and attachments are restricted to user-defined allowed roots.
  • [SAFE]: Filename sanitization automatically renames potentially dangerous files (like .exe or .pth) with a .download extension, ensuring they cannot be accidentally executed by the operating system or build tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 12:33 AM
Security Audit — agent-trust-hub — gmail-attachments