mailbox-mining
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill implements a robust redaction contract in
scripts/redaction.py. It uses a whitelist ofIDENTITY_FIELDSand explicitly refuses or 'self-heals' (removes)CONTENT_FIELDSlike message bodies and attachments. This ensures that only non-sensitive relationship metadata is written to the searchable knowledge graph. - [CREDENTIALS_UNSAFE]: The skill includes extensive regex-based detection for credentials (API keys, AWS keys, private keys) in
scripts/redaction.py. If such a pattern is detected in the processing pipeline, the skill 'fails closed' by raising aRedactionViolationand refusing to store the record. - [PRIVILEGE_ESCALATION]: The skill explicitly delegates all Gmail API access (OAuth, token management, and sending) to a separate
/gmailtool. It does not store or request its own credentials, adhering to the principle of least privilege. - [COMMAND_EXECUTION]: The skill includes an
assesscommand that audits other code for bespoke Gmail access or hardcoded credentials, promoting secure coding practices within the environment. - [PROMPT_INJECTION]: The
draft-validatecommand enforces a 'roundtable' gate, requiring a multi-party review (/ask roundtable) before any outbound message is staged. This prevents an agent from autonomously sending mail without human oversight.
Audit Metadata