gmail-export

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted email content from external senders which may contain malicious instructions designed to influence the agent.
  • Ingestion points: Email bodies, subjects, and attachment metadata are ingested during the export process as documented in SKILL.md and references/export-formats.md.
  • Boundary markers: Instructions in references/contract.md specify that content is wrapped in 'untrusted-content envelopes' using random boundaries to distinguish data from instructions.
  • Capability inventory: The skill possesses file-writing capabilities via the gmail_export tool and provides instructions for reading those files back into the conversation context.
  • Sanitization: A sanitiser is used to remove hidden elements, zero-size fonts, and off-screen text. The contract explicitly forbids following instructions found within the email bodies.
  • [DATA_EXFILTRATION]: The skill accesses sensitive email content and writes it to the local filesystem.
  • Evidence: The skill uses gmail_export to save email data to the ~/Downloads/agent-communications/ directory.
  • Mitigation: The skill enforces a 'downloads jail' as described in references/downloads-root.md, which prevents writing files outside of the designated root directory and blocks symlink-based traversal attacks.
  • [COMMAND_EXECUTION]: The skill utilizes a CLI tool to perform its primary functions.
  • Evidence: The documentation in SKILL.md and references/contract.md includes instructions for executing npx -y @agentcomms/gmail@<version> export commands.
  • Note: The executed package is a resource associated with the skill's authoring organization and is used for its intended purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 12:33 AM
Security Audit — agent-trust-hub — gmail-export