gws-gmail-triage
Pass
Audited by Gen Agent Trust Hub on Jun 25, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted data from external sources (unread emails), which presents a surface for indirect prompt injection.
- Ingestion points: Email headers (sender, subject) retrieved via the
gwstool. - Boundary markers: No specific delimiters are defined in the output format to separate untrusted content from agent instructions.
- Capability inventory: Execution of the
gwsbinary for email retrieval. - Sanitization: The skill does not explicitly mention sanitization of email content before presentation to the agent.
Audit Metadata