recipe-label-and-archive-emails

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions to execute shell commands using the gws (Google Workspace) CLI tool to list, label, and archive Gmail messages.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes data from external email senders.
  • Ingestion points: The skill searches email message content and metadata through the gws gmail users messages list command in SKILL.md.
  • Boundary markers: There are no boundary markers or instructions to ignore potential commands embedded in the email content.
  • Capability inventory: The skill uses the gws CLI to modify email labels and archive threads in SKILL.md.
  • Sanitization: The skill does not provide methods for sanitizing the ingested email data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:12 AM
Security Audit — agent-trust-hub — recipe-label-and-archive-emails