gmail-follow-ups
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process email data (subjects, addresses, and thread contents), which constitutes an untrusted external data source.
- Ingestion points: Data is ingested via
gmail_followups,gmail_thread_get, andgmail_exportas described inSKILL.mdandreferences/contract.md. - Boundary markers: The skill explicitly mandates the use of an "untrusted-content envelope with a per-call random boundary" to prevent instructions inside emails from being interpreted as agent commands.
- Capability inventory: The skill can read threads, export content to local files, and list inboxes. It is explicitly prohibited from drafting or sending emails autonomously.
- Sanitization: A dedicated sanitizer is referenced in
references/contract.mdthat removes hidden or transparent text (e.g., zero-size fonts, same-color text) and reports these attempts to the user.
Audit Metadata