gmail-organize

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill acknowledges that email content (bodies and subjects) is untrusted data that could contain malicious instructions.
  • Ingestion points: Message and thread IDs are ingested into the agent context (SKILL.md, references/contract.md).
  • Boundary markers: The skill mandates the use of an untrusted-content envelope with per-call random boundaries to isolate email data (references/contract.md).
  • Capability inventory: Tools include gmail_organise, gmail_trash, and gmail_label_create for mailbox management; sending and permanent deletion capabilities are strictly excluded (SKILL.md).
  • Sanitization: A built-in sanitizer detects and reports hidden elements, zero-size fonts, and text concealment techniques to the user before processing (references/contract.md).
  • [COMMAND_EXECUTION]: The skill uses the @agentcomms/gmail package and the agent-gmail CLI for its operations. These are recognized vendor tools for the author 'crissmoldovan'.
  • [SAFE]: The skill implements advanced safety protocols, such as requiring a dry run for any change affecting more than 10 messages or search-based selections, ensuring the user confirms the actual impact before changes are applied. It also provides a granular undo mechanism to restore previous mailbox states.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 12:33 AM
Security Audit — agent-trust-hub — gmail-organize