recipe-save-email-attachments

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs legitimate productivity tasks as described. It uses the gws command-line utility to interface with Gmail and Google Drive APIs. No credentials, obfuscation, or unauthorized network calls were detected.- [PROMPT_INJECTION]: The skill processes external data (email attachments) which is a potential surface for indirect prompt injection (Category 8). This is an inherent risk of automation tasks involving external content. Mandatory Evidence Chain: 1. Ingestion points: Gmail attachment retrieval step in SKILL.md. 2. Boundary markers: None explicitly mentioned in the recipe. 3. Capability inventory: Writing to Google Drive using gws. 4. Sanitization: Relies on underlying tools and agent platform constraints.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 01:27 PM
Security Audit — agent-trust-hub — recipe-save-email-attachments