pp-gmail

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the gmail-pp-cli binary using npx from the @mvanhorn/printing-press-library package or via go install from github.com/mvanhorn/printing-press-library. These sources are owned by the author and are considered vendor resources.\n- [COMMAND_EXECUTION]: The skill operates by executing the gmail-pp-cli binary through shell commands to interact with the Gmail API and manage a local SQLite store.\n- [DYNAMIC_EXECUTION]: The skill utilizes a Playbook system where sequences of commands are executed from JSON files with dynamic slot substitution. It also encourages the use of background execution for its metadata teaching and learning functions.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted email content (messages, attachments, and sender metadata) to generate digests and cleanup plans. While the skill includes instructions for stripping personal identifiers during its learning process, it lacks specific boundary markers when summarizing or reading message content, which is an ingestion point for potential instructions embedded in emails. Capabilities available to the agent include shell execution and mailbox modification.\n- [DATA_EXFILTRATION]: The CLI tool provides a documented --deliver webhook: feature that allows the user or agent to POST command results, including mailbox metadata, to external URLs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 04:46 AM
Security Audit — agent-trust-hub — pp-gmail