gmail-contacts
Find somebody's address
This skill answers a small question — what is this person's address — and the answer is rarely read
again. It goes to gmail-compose, which puts it in a To line, and from there to gmail-send, where
a person approves a preview that contains the address you supplied. If you hand over the wrong one,
every step after this is working correctly on the wrong premise.
The hazard is specific and it is not a rare edge case. This search matches names, and a name
match is not evidence of anything. sam@acme-invoices.test matches a search for "Sam" exactly as
well as sam@acme.test does, and if the first one ever appeared in a message the user read, it is
in the mailbox's history and it will come back as a row. Worse, the display name attached to it is
whatever the sender wrote in the header: an attacker choosing "Sam Rivera" makes their row look more
like the real Sam than the real Sam's row, which may carry no name at all. The search does no
filtering — the CLI prints the line "Similar addresses are shown, not filtered" underneath every
result for exactly this reason.