Back to skill

Security audit

Gmail Briefings

Security checks for vulnerabilities and agentic risk

Overview

This Gmail briefing skill is a small, disclosed mailbox-triage helper, but it should only be installed by someone comfortable granting it access to their Gmail data.

Install this only for an account where you intentionally want Codex to use an authenticated gog/Gmail setup to inspect unread messages and prepare replies. Replace the embedded personal email address with your own placeholder or configuration, and review any draft, archive, or flagging action before allowing changes to the mailbox.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase "check gmail" is broad and naturally overlaps with common user requests about email. In an agent environment, this can cause the skill to activate unintentionally for generic prompts, leading to unnecessary access to inbox data, email summaries, or drafting actions when the user may not have intended to invoke this specific skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document contains a personal email address in plain text without any indication that it is test data or intentionally public. Exposing personal account identifiers in operational documentation can leak private information, aid phishing or credential-stuffing attempts, and suggests the skill may rely on a real personal account for workflow access.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.