mailbox-mining

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill implements a robust redaction contract in scripts/redaction.py. It uses a whitelist of IDENTITY_FIELDS and explicitly refuses or 'self-heals' (removes) CONTENT_FIELDS like message bodies and attachments. This ensures that only non-sensitive relationship metadata is written to the searchable knowledge graph.
  • [CREDENTIALS_UNSAFE]: The skill includes extensive regex-based detection for credentials (API keys, AWS keys, private keys) in scripts/redaction.py. If such a pattern is detected in the processing pipeline, the skill 'fails closed' by raising a RedactionViolation and refusing to store the record.
  • [PRIVILEGE_ESCALATION]: The skill explicitly delegates all Gmail API access (OAuth, token management, and sending) to a separate /gmail tool. It does not store or request its own credentials, adhering to the principle of least privilege.
  • [COMMAND_EXECUTION]: The skill includes an assess command that audits other code for bespoke Gmail access or hardcoded credentials, promoting secure coding practices within the environment.
  • [PROMPT_INJECTION]: The draft-validate command enforces a 'roundtable' gate, requiring a multi-party review (/ask roundtable) before any outbound message is staged. This prevents an agent from autonomously sending mail without human oversight.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — mailbox-mining