gws-gmail-read

Pass

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill facilitates the ingestion of external data from Gmail, creating a potential vector for indirect prompt injection.
  • Ingestion points: Message bodies and headers fetched via the gws gmail +read command in SKILL.md.
  • Boundary markers: The skill does not define specific delimiters or instructional guardrails to prevent the agent from obeying commands embedded in the email content.
  • Capability inventory: The tool allows for reading and structured extraction of email data via the gws CLI.
  • Sanitization: No evidence of content filtering, escaping, or validation of the retrieved email data is provided.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 25, 2026, 09:54 AM
Security Audit — agent-trust-hub — gws-gmail-read