gws-gmail-read
Pass
Audited by Gen Agent Trust Hub on Jun 25, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill facilitates the ingestion of external data from Gmail, creating a potential vector for indirect prompt injection.
- Ingestion points: Message bodies and headers fetched via the
gws gmail +readcommand inSKILL.md. - Boundary markers: The skill does not define specific delimiters or instructional guardrails to prevent the agent from obeying commands embedded in the email content.
- Capability inventory: The tool allows for reading and structured extraction of email data via the
gwsCLI. - Sanitization: No evidence of content filtering, escaping, or validation of the retrieved email data is provided.
Audit Metadata