gws-gmail-watch
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions and metadata do not contain any malicious patterns, obfuscation, or unauthorized access attempts.\n- [PROMPT_INJECTION]: The skill enables an agent to process external data (Gmail messages), creating a surface for indirect prompt injection.\n
- Ingestion points: Gmail email content accessed via the
gwsutility (SKILL.md).\n - Boundary markers: The instructions do not define specific delimiters for separating email content from agent instructions.\n
- Capability inventory: The skill triggers the
gwsbinary and supports writing output to a local directory via the--output-dirflag.\n - Sanitization: No evidence of data sanitization or instruction filtering is present in the skill.\n- [EXTERNAL_DOWNLOADS]: The skill relies on an external binary dependency,
gws, as specified in the metadata requirements. This tool is a resource from the vendor streakyc.
Audit Metadata