gws-gmail-watch

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions and metadata do not contain any malicious patterns, obfuscation, or unauthorized access attempts.\n- [PROMPT_INJECTION]: The skill enables an agent to process external data (Gmail messages), creating a surface for indirect prompt injection.\n
  • Ingestion points: Gmail email content accessed via the gws utility (SKILL.md).\n
  • Boundary markers: The instructions do not define specific delimiters for separating email content from agent instructions.\n
  • Capability inventory: The skill triggers the gws binary and supports writing output to a local directory via the --output-dir flag.\n
  • Sanitization: No evidence of data sanitization or instruction filtering is present in the skill.\n- [EXTERNAL_DOWNLOADS]: The skill relies on an external binary dependency, gws, as specified in the metadata requirements. This tool is a resource from the vendor streakyc.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 01:27 PM
Security Audit — agent-trust-hub — gws-gmail-watch