Back to skill

Security audit

gmail-filter-architect

Security checks for vulnerabilities and agentic risk

Overview

This skill openly builds and imports Gmail filters, with real mailbox read access and mail-filter mutation disclosed and guarded by verification, backups, and rollback guidance.

Install only if you are comfortable granting Gmail read access for recent mail review and letting the agent create or import persistent Gmail filters. Review generated archive rules before import, do not apply the archive/star batch to old mail, keep the old filter backup, and verify that bills, security alerts, codes, and human replies are not being hidden.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: gmail-filter-architect
description: "Design, verify and import a complete Gmail filter system: a small emoji label taxonomy, urgent mail starred, bills/finance/infra/codes labelled, marketing and social auto-archived, forwarded accounts tagged by source. Built from a 90-day sender census of your own mailbox, every rule is checked against your real mail for misfires before import, and every archiving rule carries a shared protection group so bills, codes and security alerts are never hidden. Use for: cleaning up Gmail filters, bills landing in promotions, important mail getting archived, 'set up the best Gmail filter

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
90% confidence
Finding

Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a direct jailbreak that disables guardrails.

Content

Scanner excerpt · references/research-2026-09.zh-CN.md (reported line 39)May include surrounding context.

md
**一个关键推论:** 动作里没有"放回收件箱"。所以一旦某条过滤器把邮件归档了,没有其他过滤器能把它救回来。保护重要邮件只有两个办法:
- 在每一条会归档的过滤器里写排除组 `-{...}`;
- 或者开启 Priority Inbox 的"Override filters",让标记为重要的邮件留在收件箱。

**每条过滤器只能加一个用户标签和一个分类。** 要加多个标签就得拆成多条。来源:https://github.com/taers232c/GAMADV-XTD3/wiki/Users-Gmail-Filters

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
90% confidence
Finding

Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a direct jailbreak that disables guardrails.

Content

Scanner excerpt · references/research-2026-09.zh-CN.md (reported line 80)May include surrounding context.

md
**一个关键推论:** 动作里没有"放回收件箱"。所以一旦某条过滤器把邮件归档了,没有其他过滤器能把它救回来。保护重要邮件只有两个办法:
- 在每一条会归档的过滤器里写排除组 `-{...}`;
- 或者开启 Priority Inbox 的"Override filters",让标记为重要的邮件留在收件箱。

**每条过滤器只能加一个用户标签和一个分类。** 要加多个标签就得拆成多条。来源:https://github.com/taers232c/GAMADV-XTD3/wiki/Users-Gmail-Filters

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
90% confidence
Finding

Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a direct jailbreak that disables guardrails.

Content

Scanner excerpt · references/research-2026-09.zh-CN.md (reported line 78)May include surrounding context.

md
### 3. 标签体系

- **Jeff Su 方案(流传最广):** 只用 4 个动作型标签:Follow Up、Waiting、Read Through、Calendar。收件箱类型改为 Multiple Inboxes,按标签分区;"Filtered mail"设为"Don't override filters";重要性标记关掉。
- **Multiple Inboxes 最多 5 个分区**,每区一条查询。它和默认的分类标签页是两种互斥的收件箱类型,不能同时用。来源:https://support.google.com/mail/answer/9694882?hl=en
- **"Override filters"是个开关:** 开着时,被标为重要的邮件即使命中"跳过收件箱"也会留在收件箱。追求 inbox zero 的人通常关掉它;反过来,把它开着也可以当作重要邮件的保护网。来源:https://www.getinboxzero.com/blog/post/gmail-filters-not-working-troubleshooting-guide
- **Gmail 自带的新功能:**

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

该文件整体以中文撰写,标题和正文均默认中文输出,但没有说明这是面向特定中文用户群体,亦未提供语言/locale 选择。按自然语言政策要求,若技能内容强制特定语言而无用户选择,属于语言/locale 约束未显式获用户同意。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.