gmail-follow-ups

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process email data (subjects, addresses, and thread contents), which constitutes an untrusted external data source.
  • Ingestion points: Data is ingested via gmail_followups, gmail_thread_get, and gmail_export as described in SKILL.md and references/contract.md.
  • Boundary markers: The skill explicitly mandates the use of an "untrusted-content envelope with a per-call random boundary" to prevent instructions inside emails from being interpreted as agent commands.
  • Capability inventory: The skill can read threads, export content to local files, and list inboxes. It is explicitly prohibited from drafting or sending emails autonomously.
  • Sanitization: A dedicated sanitizer is referenced in references/contract.md that removes hidden or transparent text (e.g., zero-size fonts, same-color text) and reports these attempts to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 12:34 AM
Security Audit — agent-trust-hub — gmail-follow-ups