gws-gmail-read
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Potential for indirect prompt injection through processed email content.
- Ingestion points: The command
gws gmail +readinSKILL.mdfetches untrusted external data (email bodies and headers). - Boundary markers: Absent. The skill does not define delimiters or provide instructions to the agent to distinguish between the message data and agent commands.
- Capability inventory: The
gwstool suite, as described in the 'See Also' section, includes capabilities to send and manage emails, which could be abused if the agent obeys instructions embedded in an email. - Sanitization: Absent. There is no evidence of validation or escaping of the fetched email content before it is presented to the agent.
Audit Metadata