gmail-send

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted email draft content which could contain malicious instructions meant to hijack the agent's behavior.
  • Ingestion points: The gmail_send_prepare tool reads draft content including the body, subject, and recipients from the user's mailbox.
  • Boundary markers: The skill uses an untrusted-content envelope with per-call random boundaries and includes explicit instructions in references/contract.md to treat mail content as data, not instructions.
  • Capability inventory: The gmail_draft_send tool can perform the sensitive action of transmitting email.
  • Sanitization: A built-in sanitizer removes hidden text, zero-size fonts, and transparent characters, reporting these counts as hiddenElements and hiddenChars to alert the agent to potential concealment attempts.
  • [SAFE]: The skill adopts an exemplary security posture for high-risk operations.
  • Verbatim Previews: The procedure strictly forbids summarizing or paraphrasing the email preview, ensuring the user sees the exact recipients and content before approval.
  • Integrity Enforcement: It utilizes an expect block to verify that the draft content at the moment of sending exactly matches the version approved by the user.
  • Risk Identification: Automatically flags external recipients, first-time contacts, and lookalike domains (typosquatting detection) to prevent data exfiltration or phishing.
  • Multi-Factor Approval: Supports a confirm policy that mandates out-of-band approval via a terminal or trusted form for high-security mailboxes, which cannot be bypassed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 12:33 AM
Security Audit — agent-trust-hub — gmail-send