Back to skill

Security audit

Draft Machine

Security checks for vulnerabilities and agentic risk

Overview

This skill transparently helps create Gmail draft emails for mail merge, with sensitive but expected OAuth and package-install steps.

Before installing, make sure you trust the DraftMachine PyPI package and the linked source. During setup, confirm the Google OAuth consent asks only for the expected draft-related Gmail access, keep `~/.draftmachine` files private, run the required preview, and review all created drafts in Gmail before sending anything.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.