gmail-contacts

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from Gmail headers, contact notes, and email bodies, which constitutes an indirect prompt injection attack surface.\n
  • Ingestion points: Untrusted content enters the agent context through the gmail_contacts_search and gmail_search tools, as described in SKILL.md and references/contract.md.\n
  • Boundary markers: The skill's contract requires that external data be wrapped in an untrusted-content envelope with per-call random boundaries to ensure the agent distinguishes data from instructions.\n
  • Capability inventory: The skill allows for searching mailboxes, exporting thread content to files via gmail_export, and passing addresses to composition tools.\n
  • Sanitization: Content is passed through a sanitizer that removes hidden elements like zero-size fonts or transparent text, and reports the presence of such elements to the user to mitigate concealment attacks.\n- [EXTERNAL_DOWNLOADS]: The skill relies on the @agentcomms/gmail Node.js package (version 0.12.2) and its associated CLI tools to interact with Gmail APIs.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 12:33 AM
Security Audit — agent-trust-hub — gmail-contacts