gmail-security

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze untrusted email content, which is a known vector for indirect prompt injection attacks. However, the skill provides comprehensive mitigations.
  • Ingestion points: Untrusted data is ingested through the gmail_message_get tool in SKILL.md.
  • Boundary markers: All sender-provided text is wrapped in a mandatory <untrusted-content> envelope using random, per-call boundaries to prevent boundary escaping, as detailed in the Contract and references/injection.md.
  • Capability inventory: The skill is strictly limited to reading and analysis tasks. It explicitly prohibits the agent from taking any actions (sending, forwarding, or modifying mail) based on the email content, as stated in the Procedure Step 10.
  • Sanitization: The skill employs an advanced sanitiser that removes hidden elements and neutralizes role markers and chat tokens (e.g., System:, <|im_start|>) before the agent sees the content, reporting these modifications to the agent for risk assessment.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 12:33 AM
Security Audit — agent-trust-hub — gmail-security