Back to skill

Security audit

gmail-all-email-actions

Security checks for vulnerabilities and agentic risk

Overview

This Gmail skill is purpose-aligned, but it grants broad email read, send, forward, label, trash, and draft-deletion authority through a third-party remote service without clear confirmation gates.

Review this before installing if the connected Gmail account contains sensitive mail. Use it only with an AgentPMT account you trust, confirm recipients and content before sends, replies, forwards, and draft sends, and require clear user approval before trashing messages or deleting drafts.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (19)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 312)May include surrounding context.

md
Complete generated action schema: `./schema.md`.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description does not prominently warn that the skill can read private email content, send messages as the user, and perform destructive actions like trashing items. For a Gmail-integrated tool with broad mailbox access, weak user-facing disclosure raises the risk of surprise data exposure and unintended privileged actions in response to ambiguous prompts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation keywords are very broad and overlap with ordinary email-related tasks. In an agent ecosystem, this can cause over-selection of a highly privileged Gmail skill for vague prompts, increasing the chance of unintended email reads, sends, forwards, or mailbox modifications without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill claims supported actions such as get_instructions and get_thread that are not documented in the main Actions section. In a high-impact email tool, undocumented callable actions can cause agents or operators to invoke broader read/exfiltration behavior than they understand, especially when the tool can access inbox contents and metadata.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This skill routes Gmail operations through AgentPMT-hosted remote endpoints, meaning email content, metadata, recipients, and attachment URLs may be transmitted to external infrastructure outside the local agent environment. Because the tool can read, send, search, and modify email, the external transmission surface is inherently sensitive and materially increases confidentiality and integrity risk if the service, logs, or request handling are compromised.

Content

Scanner excerpt · SKILL.md (reported line 498)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/gmail-all-email-actions
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The documented REST invoke endpoint confirms that mailbox operations are performed via external network calls to AgentPMT infrastructure. In the context of a full-access Gmail skill, this is security-significant because private communications and account actions are delegated to a third-party service, creating exfiltration, logging, and trust-boundary concerns even if the service is legitimate.

Content

Scanner excerpt · SKILL.md (reported line 499)May include surrounding context.

md
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/gmail-all-email-actions
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The schema exposes a permanently destructive delete_draft action but does not communicate any requirement for confirmation or highlight irreversibility at the point of use. In an agent-driven context, this increases the risk of accidental or prompt-induced deletion of drafts without the user understanding the finality of the operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The forward_message action notes that source message content is included automatically, but it lacks a clear privacy/security warning that forwarding transmits original message content to new recipients. In an email skill, that omission can lead an agent or user to disclose sensitive information externally without adequate awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The reply_message action automatically uses existing thread recipient context, but the schema does not warn that a reply may send content or attachments to external recipients based on that context. This is dangerous because agents may continue sensitive conversations or attach files without the user realizing who will receive them.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The send_draft action can transmit previously stored content to recipients, but the schema does not explicitly warn that invoking it sends the draft as-is. In agentic workflows, stale or unreviewed drafts may be sent unintentionally, causing data leakage, reputational harm, or premature communication.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The send_message action directly transmits message bodies, attachments, and addressing fields, yet the schema lacks an explicit warning about external transmission and disclosure risk. Because this skill is designed for broad automated email operations, omission of this warning makes accidental exfiltration or unintended outbound communication more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The trash_message action changes mailbox state and may contribute to data loss or missed communications, but the schema does not warn users about that consequence. In an inbox-management skill, agents may aggressively triage messages, so missing cautions increase the chance of accidental loss of important email.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The high-level 'What This Tool Does' section describes draft functionality as creating, retrieving, and sending drafts, but the documented actions also include delete_draft, which permanently deletes a draft. While draft management is related to the skill's purpose, the manifest-level summary understates this destructive capability.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.