recipe-label-and-archive-emails
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions to execute shell commands using the
gws(Google Workspace) CLI tool to list, label, and archive Gmail messages. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes data from external email senders.
- Ingestion points: The skill searches email message content and metadata through the
gws gmail users messages listcommand inSKILL.md. - Boundary markers: There are no boundary markers or instructions to ignore potential commands embedded in the email content.
- Capability inventory: The skill uses the
gwsCLI to modify email labels and archive threads inSKILL.md. - Sanitization: The skill does not provide methods for sanitizing the ingested email data.
Audit Metadata