gmail-send

Warn

Audited by Snyk on Oct 5, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (medium risk: 0.30). The skill operates Gmail email sending via gmail_draft_send, which performs a direct financial or operational execution (sending an irreversible message). However, the skill incorporates documented independent service-layer authorization controls: mail delivery is gated by server-enforced policies (sendPolicy set to chat or confirm) requiring user approval, cryptographic approvalId verification, and strict expect-block matching enforced by the execution layer. Because direct operations have qualifying independent access controls, the severity is medium.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 5, 2026, 12:32 AM
Issues
1
Security Audit — snyk — gmail-send