gmail-search
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill manages the risks associated with processing untrusted external data from emails through multiple defense layers.\n
- Ingestion points: The skill ingests email subjects, snippets, and bodies via the
gmail_search,gmail_message_get, andgmail_thread_gettools as described inSKILL.md.\n - Boundary markers: As specified in
references/contract.md, all retrieved content is encapsulated within an untrusted-content envelope using a per-call random boundary to prevent the model from misinterpreting data as instructions.\n - Capability inventory: The skill's capabilities are strictly limited to read-only operations. It possesses no tools for drafting, sending, or modifying mailbox contents, which significantly restricts the impact of any potential injection.\n
- Sanitization:
references/body-pipeline.mddetails an extensive sanitization process that removes scripts, hidden elements, and invisible characters, while also flagging content concealment techniques like identical text and background colors.\n- [EXTERNAL_DOWNLOADS]: The skill relies on the@agentcomms/gmailNode.js package for its core functionality.\n - Evidence: The skill metadata in
SKILL.mdidentifies compatibility with the@agentcomms/gmail@0.13.0package.\n - Context: This package provides the foundational CLI and MCP tools required for the skill's operation. No unauthorized or suspicious remote code execution patterns were identified.
Audit Metadata