gmail-contacts
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from Gmail headers, contact notes, and email bodies, which constitutes an indirect prompt injection attack surface.\n
- Ingestion points: Untrusted content enters the agent context through the
gmail_contacts_searchandgmail_searchtools, as described in SKILL.md and references/contract.md.\n - Boundary markers: The skill's contract requires that external data be wrapped in an untrusted-content envelope with per-call random boundaries to ensure the agent distinguishes data from instructions.\n
- Capability inventory: The skill allows for searching mailboxes, exporting thread content to files via
gmail_export, and passing addresses to composition tools.\n - Sanitization: Content is passed through a sanitizer that removes hidden elements like zero-size fonts or transparent text, and reports the presence of such elements to the user to mitigate concealment attacks.\n- [EXTERNAL_DOWNLOADS]: The skill relies on the
@agentcomms/gmailNode.js package (version 0.12.2) and its associated CLI tools to interact with Gmail APIs.
Audit Metadata