gmail

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation and execution of the @membranehq/cli tool from the NPM registry to facilitate communication between the agent and the Membrane integration platform.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides the ability to ingest and process untrusted data from Gmail, which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: The agent processes external data from emails, threads, and attachments via actions such as list-messages and get-message (SKILL.md).
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the documented processing logic to isolate untrusted email content.
  • Capability inventory: The skill possesses high-privilege capabilities including sending emails (send-message), deleting records (delete-message, delete-thread), and performing arbitrary API requests via the membrane request proxy (SKILL.md).
  • Sanitization: The instructions do not define specific sanitization or validation steps for content retrieved from the Gmail API before it is processed by the AI.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 06:17 PM
Security Audit — agent-trust-hub — gmail