gmail-compose
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill identifies and mitigates indirect prompt injection risks through a mandatory contract. Untrusted data enters the agent context via tools like
gmail_draft_replywhich ingest existing email messages. The skill employs explicit boundary markers by instructing the agent to treat all mail content as data rather than instructions and requires presenting verbatim previews to the user within code fences. The agent's capabilities are limited to draft management (create, update, delete) and it is strictly prohibited from executing send operations. Sanitization is enforced by a parser that detects and reports concealed content, including hidden elements, zero-size characters, and text matching background colors. - [COMMAND_EXECUTION]: Access to local files for the purpose of adding attachments is strictly controlled by a "jail" system. Files must be located within explicitly allowed root directories and are blocked if they reside in denied paths, preventing unauthorized file access or exfiltration of sensitive system files.
- [REMOTE_CODE_EXECUTION]: The skill declares a dependency on the
@agentcomms/gmailNode.js package. This package is consistent with the skill's authorship by crissmoldovan and provides the necessary CLI/MCP tools for Gmail API interaction without introducing arbitrary remote execution vulnerabilities.
Audit Metadata