gws-gmail-read

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Potential for indirect prompt injection through processed email content.
  • Ingestion points: The command gws gmail +read in SKILL.md fetches untrusted external data (email bodies and headers).
  • Boundary markers: Absent. The skill does not define delimiters or provide instructions to the agent to distinguish between the message data and agent commands.
  • Capability inventory: The gws tool suite, as described in the 'See Also' section, includes capabilities to send and manage emails, which could be abused if the agent obeys instructions embedded in an email.
  • Sanitization: Absent. There is no evidence of validation or escaping of the fetched email content before it is presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 05:05 PM
Security Audit — agent-trust-hub — gws-gmail-read