Back to skill

Security audit

Gmail To Outlook

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Gmail-to-Microsoft 365 migration guide with some operational safety gaps, not evidence of hidden or malicious behavior.

Installers should understand that this skill is for real email-system administration. Use it only with authorized Google Workspace, Microsoft 365, and DNS access; do not email passwords or service-account keys in plaintext; back up existing DNS records before cutover; and perform MX changes only during a planned window after mailbox readiness and rollback steps are confirmed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The templates include user communications, reports, setup instructions, and migration operational details involving credentials, service accounts, mailbox contents, and account identifiers, but they do not explicitly instruct operators to minimize, protect, and carefully handle sensitive user data during the migration. In a mail migration context, this omission can lead to unsafe sharing of credentials, unnecessary exposure of account details in reports or emails, and weak handling of personal/business data during a high-risk administrative process.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The instruction to 'Remove ALL existing MX records' is operationally destructive and can interrupt inbound mail delivery if performed prematurely or incorrectly. In a migration skill, this is especially risky because users may follow it as a direct cutover command without prerequisites, rollback guidance, propagation warnings, or confirmation that Exchange Online mail flow and recipient provisioning are fully ready.