Gmail

Security checks across malware telemetry and agentic risk

Overview

This Gmail skill is not deceptive, but it gives agents broad mailbox access, including permanent deletion and raw Gmail API requests, without enough confirmation guardrails.

Install only if you trust Membrane with delegated Gmail access. Use the narrowest OAuth scope available, connect only the intended mailbox, prefer curated actions over proxy requests, and require explicit user confirmation before sending, modifying, or permanently deleting anything.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill advertises permanently destructive Gmail actions like deleting messages, threads, drafts, and labels without any warning or confirmation guidance. In an agent setting, this increases the chance that a loosely scoped user request or planner mistake results in irreversible mailbox data loss.

VirusTotal

52/52 vendors flagged this skill as clean.

View on VirusTotal