gmail-setup
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill manages Google OAuth connectivity and mailbox integration for the agent. It implements strong security measures, such as explicitly forbidding the agent from ever reading or echoing client secrets or refresh tokens.
- [COMMAND_EXECUTION]: The skill executes the
agent-gmailCLI for configuration tasks. Security is enforced through a "change approval" protocol: sensitive operations (like mailbox removal or OAuth client changes) return a preview and an "approvalId", requiring explicit user confirmation before execution. - [INDIRECT_PROMPT_INJECTION]: The skill manages the risk of untrusted data from email bodies by defining a data handling contract. Ingestion occurs via search and profile tools; boundary markers (random per-call strings) and content sanitization (removing hidden or transparent text) are employed to ensure that mailbox content is treated as data and not instructions. Capabilities include writing configuration files and registering MCP servers.
- [EXTERNAL_DOWNLOADS]: The skill utilizes the "@agentcomms/gmail" package. This resource belongs to the author's official namespace ("crissmoldovan") and is essential for the skill's defined functionality.
Audit Metadata