gmail-thread-analysis
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted email content which could contain malicious instructions aimed at overriding agent behavior. Evidence includes:
- Ingestion points: Retrieval of message bodies and subjects via
gmail_thread_getandgmail_message_get(SKILL.md, Procedure section). - Boundary markers: Use of an 'untrusted-content envelope' with random boundaries to isolate external data as mandated by the shared contract (references/contract.md).
- Capability inventory: Access to email reading and local file writing via
gmail_export, with strict restrictions against autonomous drafting or sending (references/contract.md). - Sanitization: An active pipeline for removing hidden elements, invisible characters, and transparent text to prevent obfuscated instructions from reaching the model (references/contract.md).
- [REMOTE_CODE_EXECUTION]: The documentation references runtime execution of remote packages via
npxfor setup and CLI access. - Execution method: The skill contract describes using
npx -y @agentcomms/gmail@<version>to fetch and run official platform tools from the npm registry. This is a documented method for accessing CLI tools when the primary server is unavailable.
Audit Metadata