Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md Complete generated action schema: `./schema.md`.
Security audit
Security checks for vulnerabilities and agentic risk
This Gmail skill is purpose-aligned, but it grants broad email read, send, forward, label, trash, and draft-deletion authority through a third-party remote service without clear confirmation gates.
Review this before installing if the connected Gmail account contains sensitive mail. Use it only with an AgentPMT account you trust, confirm recipients and content before sends, replies, forwards, and draft sends, and require clear user approval before trashing messages or deleting drafts.
Referenced artifact was not completely inspected
Complete generated action schema: `./schema.md`.
The description does not prominently warn that the skill can read private email content, send messages as the user, and perform destructive actions like trashing items. For a Gmail-integrated tool with broad mailbox access, weak user-facing disclosure raises the risk of surprise data exposure and unintended privileged actions in response to ambiguous prompts.
The activation keywords are very broad and overlap with ordinary email-related tasks. In an agent ecosystem, this can cause over-selection of a highly privileged Gmail skill for vague prompts, increasing the chance of unintended email reads, sends, forwards, or mailbox modifications without sufficiently explicit user intent.
The skill claims supported actions such as get_instructions and get_thread that are not documented in the main Actions section. In a high-impact email tool, undocumented callable actions can cause agents or operators to invoke broader read/exfiltration behavior than they understand, especially when the tool can access inbox contents and metadata.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
This skill routes Gmail operations through AgentPMT-hosted remote endpoints, meaning email content, metadata, recipients, and attachment URLs may be transmitted to external infrastructure outside the local agent environment. Because the tool can read, send, search, and modify email, the external transmission surface is inherently sensitive and materially increases confidentiality and integrity risk if the service, logs, or request handling are compromised.
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/gmail-all-email-actions
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
The documented REST invoke endpoint confirms that mailbox operations are performed via external network calls to AgentPMT infrastructure. In the context of a full-access Gmail skill, this is security-significant because private communications and account actions are delegated to a third-party service, creating exfiltration, logging, and trust-boundary concerns even if the service is legitimate.
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/gmail-all-email-actions
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase
The schema exposes a permanently destructive delete_draft action but does not communicate any requirement for confirmation or highlight irreversibility at the point of use. In an agent-driven context, this increases the risk of accidental or prompt-induced deletion of drafts without the user understanding the finality of the operation.
The forward_message action notes that source message content is included automatically, but it lacks a clear privacy/security warning that forwarding transmits original message content to new recipients. In an email skill, that omission can lead an agent or user to disclose sensitive information externally without adequate awareness.
The reply_message action automatically uses existing thread recipient context, but the schema does not warn that a reply may send content or attachments to external recipients based on that context. This is dangerous because agents may continue sensitive conversations or attach files without the user realizing who will receive them.
The send_draft action can transmit previously stored content to recipients, but the schema does not explicitly warn that invoking it sends the draft as-is. In agentic workflows, stale or unreviewed drafts may be sent unintentionally, causing data leakage, reputational harm, or premature communication.
The send_message action directly transmits message bodies, attachments, and addressing fields, yet the schema lacks an explicit warning about external transmission and disclosure risk. Because this skill is designed for broad automated email operations, omission of this warning makes accidental exfiltration or unintended outbound communication more likely.
The trash_message action changes mailbox state and may contribute to data loss or missed communications, but the schema does not warn users about that consequence. In an inbox-management skill, agents may aggressively triage messages, so missing cautions increase the chance of accidental loss of important email.
The high-level 'What This Tool Does' section describes draft functionality as creating, retrieving, and sending drafts, but the documented actions also include delete_draft, which permanently deletes a draft. While draft management is related to the skill's purpose, the manifest-level summary understates this destructive capability.
No suspicious patterns detected.