gmail-send
Warn
Audited by Snyk on Oct 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (medium risk: 0.30). The skill operates Gmail email sending via
gmail_draft_send, which performs a direct financial or operational execution (sending an irreversible message). However, the skill incorporates documented independent service-layer authorization controls: mail delivery is gated by server-enforced policies (sendPolicyset tochatorconfirm) requiring user approval, cryptographicapprovalIdverification, and strict expect-block matching enforced by the execution layer. Because direct operations have qualifying independent access controls, the severity is medium.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata