skills/openai/plugins/gmail/Gen Agent Trust Hub

gmail

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [Indirect Prompt Injection Surface]: The skill ingests and processes content from external emails, which is a potential vector for indirect prompt injection attacks. If an email contains malicious instructions, the agent could potentially be influenced to perform unintended actions. The skill documentation explicitly mandates user confirmation for all state-changing operations (send, archive, delete, label), which serves as a critical security boundary.
  • [Controlled Data Operations]: The skill is designed to interact only with the user's authenticated Gmail account. It includes specific workflows to handle pasted URLs safely by attempting exact-ID lookups rather than broad searches, which minimizes the risk of processing unintended or malicious data contexts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 03:18 PM
Security Audit — agent-trust-hub — gmail