gmail-access

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSPERSISTENCEDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes various local shell commands and scripts to perform its tasks.
  • Evidence: Executes bun install and bun run build to set up and compile the Gmail CLI tool (SKILL.md).
  • Evidence: Runs shell commands via bash "${GMAIL_TOKEN_SCRIPT}" using a path provided by an environment variable (SKILL.md).
  • Evidence: Executes an attribution parser using bun scripts/attribution-parse.ts (SKILL.md).
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from an external source (Gmail) which could be used to influence agent behavior.
  • Ingestion points: Email bodies, snippets, and metadata are retrieved via the Gmail API (SKILL.md).
  • Boundary markers: The skill does not define explicit delimiters or "ignore" instructions when interpolating email content into the agent's context.
  • Capability inventory: The agent has access to Bash, Write, and AskUserQuestion tools.
  • Sanitization: No sanitization of ingested email content is specified.
  • Vulnerability: The "Self-Evolving Skill" section in SKILL.md instructs the agent to modify the skill's own instructions based on runtime feedback, which could be manipulated by malicious content within an email.
  • [EXTERNAL_DOWNLOADS]: The skill downloads external code and dependencies during its setup phase.
  • Evidence: The agent is instructed to run bun install to download Node.js packages from a remote registry (SKILL.md).
  • [PERSISTENCE]: The skill employs mechanisms to maintain access and state across sessions.
  • Evidence: Mentions an hourly refresher via launchd to maintain valid OAuth tokens (SKILL.md).
  • Evidence: The "Self-Evolving Skill" instruction allows the agent to make persistent changes to the SKILL.md instruction file.
  • [DYNAMIC_EXECUTION]: The skill involves the dynamic execution of scripts and compiled binaries.
  • Evidence: Compiles source code at runtime via bun run build.
  • Evidence: Executes an inline Python snippet to check the status of cached OAuth tokens (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 12:42 PM
Security Audit — agent-trust-hub — gmail-access