gmail
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation and execution of the
@membranehq/clitool from the NPM registry to facilitate communication between the agent and the Membrane integration platform. - [INDIRECT_PROMPT_INJECTION]: The skill provides the ability to ingest and process untrusted data from Gmail, which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: The agent processes external data from emails, threads, and attachments via actions such as
list-messagesandget-message(SKILL.md). - Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the documented processing logic to isolate untrusted email content.
- Capability inventory: The skill possesses high-privilege capabilities including sending emails (
send-message), deleting records (delete-message,delete-thread), and performing arbitrary API requests via themembrane requestproxy (SKILL.md). - Sanitization: The instructions do not define specific sanitization or validation steps for content retrieved from the Gmail API before it is processed by the AI.
Audit Metadata