Back to skill

Security audit

Howtoletmyagent Secure Gmail Access

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only companion skill that openly guides Gmail OAuth setup and warns users to approve sensitive account changes carefully.

Before installing, review the linked Gmail OAuth article and any scopes the agent proposes. Approve Google Cloud and Gmail account changes manually, use the narrowest Gmail permissions that meet your need, and do not paste OAuth secrets or tokens into chat unless you understand the exposure.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.