gmail-organize
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill acknowledges that email content (bodies and subjects) is untrusted data that could contain malicious instructions.
- Ingestion points: Message and thread IDs are ingested into the agent context (SKILL.md, references/contract.md).
- Boundary markers: The skill mandates the use of an untrusted-content envelope with per-call random boundaries to isolate email data (references/contract.md).
- Capability inventory: Tools include
gmail_organise,gmail_trash, andgmail_label_createfor mailbox management; sending and permanent deletion capabilities are strictly excluded (SKILL.md). - Sanitization: A built-in sanitizer detects and reports hidden elements, zero-size fonts, and text concealment techniques to the user before processing (references/contract.md).
- [COMMAND_EXECUTION]: The skill uses the
@agentcomms/gmailpackage and theagent-gmailCLI for its operations. These are recognized vendor tools for the author 'crissmoldovan'. - [SAFE]: The skill implements advanced safety protocols, such as requiring a dry run for any change affecting more than 10 messages or search-based selections, ensuring the user confirms the actual impact before changes are applied. It also provides a granular undo mechanism to restore previous mailbox states.
Audit Metadata