gmail-search

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill manages the risks associated with processing untrusted external data from emails through multiple defense layers.\n
  • Ingestion points: The skill ingests email subjects, snippets, and bodies via the gmail_search, gmail_message_get, and gmail_thread_get tools as described in SKILL.md.\n
  • Boundary markers: As specified in references/contract.md, all retrieved content is encapsulated within an untrusted-content envelope using a per-call random boundary to prevent the model from misinterpreting data as instructions.\n
  • Capability inventory: The skill's capabilities are strictly limited to read-only operations. It possesses no tools for drafting, sending, or modifying mailbox contents, which significantly restricts the impact of any potential injection.\n
  • Sanitization: references/body-pipeline.md details an extensive sanitization process that removes scripts, hidden elements, and invisible characters, while also flagging content concealment techniques like identical text and background colors.\n- [EXTERNAL_DOWNLOADS]: The skill relies on the @agentcomms/gmail Node.js package for its core functionality.\n
  • Evidence: The skill metadata in SKILL.md identifies compatibility with the @agentcomms/gmail@0.13.0 package.\n
  • Context: This package provides the foundational CLI and MCP tools required for the skill's operation. No unauthorized or suspicious remote code execution patterns were identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 12:33 AM
Security Audit — agent-trust-hub — gmail-search