skills/dustland/openviber/gmail/Gen Agent Trust Hub

gmail

Pass

Audited by Gen Agent Trust Hub on Apr 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses official Google OAuth authentication and standard API scopes for Gmail access, which is the recommended secure method for integrations of this type.- [DATA_EXFILTRATION]: While the skill includes tools for sending emails, this is a core documented functionality requested by the gmail.send OAuth scope. No evidence of unauthorized or hidden data exfiltration was found.- [PROMPT_INJECTION]: The skill's gmail_read tool creates an ingestion point for external data (email bodies). This represents a surface for indirect prompt injection, where an external attacker could send an email containing instructions intended to manipulate the agent's behavior. The skill does not currently specify boundary markers or sanitization instructions to mitigate this inherent risk, although this is a common characteristic of communication integrations.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 2, 2026, 10:32 AM
Security Audit — agent-trust-hub — gmail