gmail-triage
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted email content (subjects, snippets, and bodies), which constitutes an indirect prompt injection attack surface. However, the skill implements robust, defense-in-depth mitigations.
- Ingestion points: Untrusted data enters the agent's context through the
gmail_searchandgmail_message_gettools as described in the procedure steps of SKILL.md. - Boundary markers: Content is handled within an untrusted-content envelope using per-call random boundaries. The skill instructions explicitly state that mail content is data and never instructions (references/contract.md, section 2).
- Capability inventory: The skill can read mailbox data and export content to local files via
gmail_export. It intentionally lacks write access, requiring a separate skill (gmail-organize) to apply proposed changes only after human approval. - Sanitization: The skill uses a sanitizer to identify and remove hidden, transparent, or zero-width characters and is programmed to report these detections to the user as potential concealment indicators.
Audit Metadata