Back to skill

Security audit

Gmail Integration

Security checks for vulnerabilities and agentic risk

Overview

This Gmail skill is purpose-aligned at a high level, but it overstates OAuth support and has unsafe email-sending details that warrant review before installation.

Review before installing. This does not show malicious exfiltration or persistence, but it handles Gmail actions and OAuth client secrets poorly. Install only if you are comfortable debugging or hardening the OAuth flow, adding explicit confirmation before sends, and fixing raw email header construction.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
gmail.py:20
Finding

CRLF Email Header Injection in Outbound Message Construction

Content
View full analysis
Remediation
View remediation
None: if "\r" in value or "\n" in value: raise ValueError(f"{field} contains prohibited control characters") reject_header_controls(to, "to") reject_header_controls(subject, "subject") message = EmailMessage() message["To"] = to message["Subject"] = subject message.set_content(body) encoded = base64.urlsafe_b64encode(message.as_bytes()).decode("ascii") payload = {"raw": encoded} ``` ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
gmail.py:5
Finding

Incomplete OAuth Implementation Unnecessarily Loads a Client Secret and Sends Unauthenticated Requests

Content
View full analysis
Dict[str, Any]: import requests if not requests: return {"success": False, "error": "requests not available"} url = "https://gmail.googleapis.com/gmail/v1/users/me/messages.send" import base64 import json msg = f"From: me\r\nTo: {to}\r\nSubject: {subject}\r\n\r\n{body}" encoded = base64.urlsafe_b64encode(msg.encode("utf-8")).decode("utf-8") payload = {"raw": encoded} try: loop = asyncio.get_event_loop() resp = await loop.run_in_executor(None, lambda: requests.post(url, json=payload, timeout=30)) if resp.status_code == 200: return {"success": True, "message_id": resp.json().get("id")} return {"success": False, "error": resp.text} ``` The same authentication omission is present in the other Gmail requests: ```python resp = await loop.run_in_executor(None, lambda: requests.get(url, params={"maxResults": max_results}, timeout=30)) ``` ```python resp = await loop.run_in_executor(None, lambda: requests.post(url, json=payload, timeout=30)) ``` ### Technical Analysis The Skill documentation claims “full OAuth2 support,” but the implementation does not perform an OAuth authorization flow, exchange an authorization code, refresh an access token, or attach an `Authorization: Bearer ...` header to Gmail ...[truncated 2462 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill claims 'full OAuth2 support' and broader Gmail automation capabilities, but the described implementation appears incomplete and may interact with Gmail endpoints without proper authenticated flow handling. Security-relevant capability overstatement can mislead users into trusting a workflow that does not correctly implement authorization, increasing the chance of unsafe deployment, broken auth handling, or ad hoc secret usage.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill claims full OAuth2 support, but the implementation never performs an OAuth2 flow, never exchanges credentials for an access token, and never attaches an Authorization header to Gmail API requests. This is dangerous because it misrepresents the security model and can lead to broken authentication, insecure future patches, or developers/users assuming Gmail operations are authenticated when they are not.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares access to environment variables and implicitly requires network access, but it does not declare any tool scope or permissions boundary in the manifest. This weakens reviewability and can cause users or orchestrators to grant broader capabilities than expected, which is risky for a skill that handles email and OAuth client secrets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description and usage examples do not clearly warn that the skill can send email on the user's behalf. For an email-integrated skill, lack of prominent user warning reduces informed consent and increases the risk of unintended outbound communication, impersonation, or social engineering abuse through normal-looking automation prompts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code sends email content and recipient data to the Gmail API, which is a safety-relevant outbound network action affecting user communications. The implementation includes no confirmation prompt, user-visible logging, or explanatory comment/docstring disclosing that message contents will be transmitted.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · gmail.py (reported line 28)May include surrounding context.

python
payload = {"raw": encoded}
        try:
            loop = asyncio.get_event_loop()
            resp = await loop.run_in_executor(None, lambda: requests.post(url, json=payload, timeout=30))
            if resp.status_code == 200:
                return {"success": True, "message_id": resp.json().get("id")}
            return {"success": False, "error": resp.text}

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · gmail.py (reported line 59)May include surrounding context.

python
payload = {"raw": encoded}
        try:
            loop = asyncio.get_event_loop()
            resp = await loop.run_in_executor(None, lambda: requests.post(url, json=payload, timeout=30))
            if resp.status_code == 200:
                return {"success": True, "message_id": resp.json().get("id")}
            return {"success": False, "error": resp.text}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description exposes high-impact capabilities (sending email and accessing mailbox contents) without clearly warning the user about those actions. This can mislead users about the scope of access they are granting and increases the risk of unintended data exposure or unauthorized outbound communication through the connected Gmail account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This function performs a network request to Gmail to retrieve message listings, which accesses user mailbox data. There is no visible warning, logging, or explanatory comment indicating that email metadata will be fetched from the user's account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Creating a Gmail label changes the state of the user's account, which is a write operation with user-impacting effects. The code provides no confirmation prompt, user-visible log, or explanatory documentation warning that it will create labels remotely.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.