gmail-thread-analysis

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted email content which could contain malicious instructions aimed at overriding agent behavior. Evidence includes:
  • Ingestion points: Retrieval of message bodies and subjects via gmail_thread_get and gmail_message_get (SKILL.md, Procedure section).
  • Boundary markers: Use of an 'untrusted-content envelope' with random boundaries to isolate external data as mandated by the shared contract (references/contract.md).
  • Capability inventory: Access to email reading and local file writing via gmail_export, with strict restrictions against autonomous drafting or sending (references/contract.md).
  • Sanitization: An active pipeline for removing hidden elements, invisible characters, and transparent text to prevent obfuscated instructions from reaching the model (references/contract.md).
  • [REMOTE_CODE_EXECUTION]: The documentation references runtime execution of remote packages via npx for setup and CLI access.
  • Execution method: The skill contract describes using npx -y @agentcomms/gmail@<version> to fetch and run official platform tools from the npm registry. This is a documented method for accessing CLI tools when the primary server is unavailable.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 12:33 AM
Security Audit — agent-trust-hub — gmail-thread-analysis