gmail-export
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted email content from external senders which may contain malicious instructions designed to influence the agent.
- Ingestion points: Email bodies, subjects, and attachment metadata are ingested during the export process as documented in
SKILL.mdandreferences/export-formats.md. - Boundary markers: Instructions in
references/contract.mdspecify that content is wrapped in 'untrusted-content envelopes' using random boundaries to distinguish data from instructions. - Capability inventory: The skill possesses file-writing capabilities via the
gmail_exporttool and provides instructions for reading those files back into the conversation context. - Sanitization: A sanitiser is used to remove hidden elements, zero-size fonts, and off-screen text. The contract explicitly forbids following instructions found within the email bodies.
- [DATA_EXFILTRATION]: The skill accesses sensitive email content and writes it to the local filesystem.
- Evidence: The skill uses
gmail_exportto save email data to the~/Downloads/agent-communications/directory. - Mitigation: The skill enforces a 'downloads jail' as described in
references/downloads-root.md, which prevents writing files outside of the designated root directory and blocks symlink-based traversal attacks. - [COMMAND_EXECUTION]: The skill utilizes a CLI tool to perform its primary functions.
- Evidence: The documentation in
SKILL.mdandreferences/contract.mdincludes instructions for executingnpx -y @agentcomms/gmail@<version> exportcommands. - Note: The executed package is a resource associated with the skill's authoring organization and is used for its intended purpose.
Audit Metadata