gmail-triage

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted email content (subjects, snippets, and bodies), which constitutes an indirect prompt injection attack surface. However, the skill implements robust, defense-in-depth mitigations.
  • Ingestion points: Untrusted data enters the agent's context through the gmail_search and gmail_message_get tools as described in the procedure steps of SKILL.md.
  • Boundary markers: Content is handled within an untrusted-content envelope using per-call random boundaries. The skill instructions explicitly state that mail content is data and never instructions (references/contract.md, section 2).
  • Capability inventory: The skill can read mailbox data and export content to local files via gmail_export. It intentionally lacks write access, requiring a separate skill (gmail-organize) to apply proposed changes only after human approval.
  • Sanitization: The skill uses a sanitizer to identify and remove hidden, transparent, or zero-width characters and is programmed to report these detections to the user as potential concealment indicators.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 12:33 AM
Security Audit — agent-trust-hub — gmail-triage