gmail-send
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted email draft content which could contain malicious instructions meant to hijack the agent's behavior.
- Ingestion points: The
gmail_send_preparetool reads draft content including the body, subject, and recipients from the user's mailbox. - Boundary markers: The skill uses an untrusted-content envelope with per-call random boundaries and includes explicit instructions in
references/contract.mdto treat mail content as data, not instructions. - Capability inventory: The
gmail_draft_sendtool can perform the sensitive action of transmitting email. - Sanitization: A built-in sanitizer removes hidden text, zero-size fonts, and transparent characters, reporting these counts as
hiddenElementsandhiddenCharsto alert the agent to potential concealment attempts. - [SAFE]: The skill adopts an exemplary security posture for high-risk operations.
- Verbatim Previews: The procedure strictly forbids summarizing or paraphrasing the email preview, ensuring the user sees the exact recipients and content before approval.
- Integrity Enforcement: It utilizes an
expectblock to verify that the draft content at the moment of sending exactly matches the version approved by the user. - Risk Identification: Automatically flags external recipients, first-time contacts, and lookalike domains (typosquatting detection) to prevent data exfiltration or phishing.
- Multi-Factor Approval: Supports a
confirmpolicy that mandates out-of-band approval via a terminal or trusted form for high-security mailboxes, which cannot be bypassed by the agent.
Audit Metadata