gmail-security
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze untrusted email content, which is a known vector for indirect prompt injection attacks. However, the skill provides comprehensive mitigations.
- Ingestion points: Untrusted data is ingested through the
gmail_message_gettool inSKILL.md. - Boundary markers: All sender-provided text is wrapped in a mandatory
<untrusted-content>envelope using random, per-call boundaries to prevent boundary escaping, as detailed in theContractandreferences/injection.md. - Capability inventory: The skill is strictly limited to reading and analysis tasks. It explicitly prohibits the agent from taking any actions (sending, forwarding, or modifying mail) based on the email content, as stated in the
ProcedureStep 10. - Sanitization: The skill employs an advanced sanitiser that removes hidden elements and neutralizes role markers and chat tokens (e.g.,
System:,<|im_start|>) before the agent sees the content, reporting these modifications to the agent for risk assessment.
Audit Metadata