Back to skill

Security audit

Gmail Lead Desk

Security checks for vulnerabilities and agentic risk

Overview

This Gmail helper uses AISA and Gmail OAuth for inbox triage, drafting, sending, and labeling, with scoped instructions and confirmation requirements for writes.

Install only if you are comfortable connecting Gmail through the AISA gateway. Use a protected AISA API key, avoid pasting secrets into shared terminals, review draft recipients and bodies before confirming sends, and do not upload confidential attachments unless that third-party transfer is approved.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (30)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide tells users to place a live API key in shell environment variables but provides no warning about credential sensitivity, shell history exposure, process inspection, shared terminal sessions, or secure cleanup. In a skill that grants access to Gmail via a gateway, mishandled credentials could let an attacker invoke mailbox-reading or mailbox-modifying operations through the connected account.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/connect_and_execute.md (reported line 26)May include surrounding context.

0. Verify API key (optional)

bash
curl "https://api.aisa.one/apis/v1/composio/auth/session/info" \
  -H "Authorization: Bearer $AISA_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/connect_and_execute.md (reported line 81)May include surrounding context.

Confirm with user before POST.

bash
curl -X POST "https://api.aisa.one/apis/v1/composio/connected_accounts/link" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
76% confidence
Finding

This endpoint specifically accepts user text for remote processing, which creates a distinct data-exposure risk compared with standard metadata or control-plane calls. In a Gmail skill context, natural-language prompts may contain copied email contents or sensitive customer details, making the lack of warning materially more dangerous.

Content

Scanner excerpt · references/connect_and_execute.md (reported line 154)May include surrounding context.

Optional — NL argument generation:

bash
curl -X POST "https://api.aisa.one/apis/v1/composio/tools/execute/GMAIL_FETCH_EMAILS/input" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "text": "List 10 unread inbox emails" }'

External Transmission

Medium
Category
Data Exfiltration
Confidence
76% confidence
Finding

This endpoint specifically accepts user text for remote processing, which creates a distinct data-exposure risk compared with standard metadata or control-plane calls. In a Gmail skill context, natural-language prompts may contain copied email contents or sensitive customer details, making the lack of warning materially more dangerous.

Content

Scanner excerpt · references/connect_and_execute.md (reported line 154)May include surrounding context.

Optional — NL argument generation:

bash
curl -X POST "https://api.aisa.one/apis/v1/composio/tools/execute/GMAIL_FETCH_EMAILS/input" \
  -H "Authorization: Bearer $AISA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "text": "List 10 unread inbox emails" }'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The attachment workflow directs users to upload files through the AISA gateway and then to a presigned URL, but it does not clearly warn that file contents leave the local environment and are transmitted to external infrastructure. For a Gmail support/sales skill, attachments may contain sensitive customer data, contracts, or internal documents, so missing disclosure increases the risk of unintended data exfiltration.

Content

No source excerpt is available for this finding.

Indirect Prompt Extraction

Medium
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains patterns that could indirectly extract system prompts through rephrasing, translation, summarization, or side-channel techniques.

Content

Scanner excerpt · references/gmail_gotchas.md (reported line 71)May include surrounding context.

md
- `GMAIL_FETCH_EMAILS` results are **not** guaranteed sorted by date — sort by `internalDate` when showing "oldest first".
- `messages` may be absent or empty — valid zero-result state.
- Large mailboxes: `include_payload: false` first, then hydrate selected threads/messages.
- Body in payload is **base64url** in `payload.parts` — decode with URL-safe base64 rules.

Default sales noise filter:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/connect_and_execute.md (reported line 26)May include surrounding context.

md
Only these `tool_slug` values may be used by **gmail-lead-desk**. For any other Gmail tool, ask the user and default to **refuse** unless they explicitly need advanced mailbox admin.

**Schema:** `GET https://api.aisa.one/apis/v1/composio/tools/{tool_slug}`  
**Execute:** `POST https://api.aisa.one/apis/v1/composio/tools/execute/{tool_slug}` — see [`connect_and_execute.md`](./connect_and_execute.md).

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/connect_and_execute.md (reported line 39)May include surrounding context.

md
Only these `tool_slug` values may be used by **gmail-lead-desk**. For any other Gmail tool, ask the user and default to **refuse** unless they explicitly need advanced mailbox admin.

**Schema:** `GET https://api.aisa.one/apis/v1/composio/tools/{tool_slug}`  
**Execute:** `POST https://api.aisa.one/apis/v1/composio/tools/execute/{tool_slug}` — see [`connect_and_execute.md`](./connect_and_execute.md).

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/connect_and_execute.md (reported line 50)May include surrounding context.

md
Only these `tool_slug` values may be used by **gmail-lead-desk**. For any other Gmail tool, ask the user and default to **refuse** unless they explicitly need advanced mailbox admin.

**Schema:** `GET https://api.aisa.one/apis/v1/composio/tools/{tool_slug}`  
**Execute:** `POST https://api.aisa.one/apis/v1/composio/tools/execute/{tool_slug}` — see [`connect_and_execute.md`](./connect_and_execute.md).

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/connect_and_execute.md (reported line 64)May include surrounding context.

md
Only these `tool_slug` values may be used by **gmail-lead-desk**. For any other Gmail tool, ask the user and default to **refuse** unless they explicitly need advanced mailbox admin.

**Schema:** `GET https://api.aisa.one/apis/v1/composio/tools/{tool_slug}`  
**Execute:** `POST https://api.aisa.one/apis/v1/composio/tools/execute/{tool_slug}` — see [`connect_and_execute.md`](./connect_and_execute.md).

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/connect_and_execute.md (reported line 81)May include surrounding context.

md
Only these `tool_slug` values may be used by **gmail-lead-desk**. For any other Gmail tool, ask the user and default to **refuse** unless they explicitly need advanced mailbox admin.

**Schema:** `GET https://api.aisa.one/apis/v1/composio/tools/{tool_slug}`  
**Execute:** `POST https://api.aisa.one/apis/v1/composio/tools/execute/{tool_slug}` — see [`connect_and_execute.md`](./connect_and_execute.md).

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/connect_and_execute.md (reported line 94)May include surrounding context.

md
Only these `tool_slug` values may be used by **gmail-lead-desk**. For any other Gmail tool, ask the user and default to **refuse** unless they explicitly need advanced mailbox admin.

**Schema:** `GET https://api.aisa.one/apis/v1/composio/tools/{tool_slug}`  
**Execute:** `POST https://api.aisa.one/apis/v1/composio/tools/execute/{tool_slug}` — see [`connect_and_execute.md`](./connect_and_execute.md).

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/connect_and_execute.md (reported line 107)May include surrounding context.

md
Only these `tool_slug` values may be used by **gmail-lead-desk**. For any other Gmail tool, ask the user and default to **refuse** unless they explicitly need advanced mailbox admin.

**Schema:** `GET https://api.aisa.one/apis/v1/composio/tools/{tool_slug}`  
**Execute:** `POST https://api.aisa.one/apis/v1/composio/tools/execute/{tool_slug}` — see [`connect_and_execute.md`](./connect_and_execute.md).

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/connect_and_execute.md (reported line 116)May include surrounding context.

md
Only these `tool_slug` values may be used by **gmail-lead-desk**. For any other Gmail tool, ask the user and default to **refuse** unless they explicitly need advanced mailbox admin.

**Schema:** `GET https://api.aisa.one/apis/v1/composio/tools/{tool_slug}`  
**Execute:** `POST https://api.aisa.one/apis/v1/composio/tools/execute/{tool_slug}` — see [`connect_and_execute.md`](./connect_and_execute.md).

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/connect_and_execute.md (reported line 129)May include surrounding context.

md
Only these `tool_slug` values may be used by **gmail-lead-desk**. For any other Gmail tool, ask the user and default to **refuse** unless they explicitly need advanced mailbox admin.

**Schema:** `GET https://api.aisa.one/apis/v1/composio/tools/{tool_slug}`  
**Execute:** `POST https://api.aisa.one/apis/v1/composio/tools/execute/{tool_slug}` — see [`connect_and_execute.md`](./connect_and_execute.md).

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/tool_whitelist.md (reported line 5)May include surrounding context.

md
Only these `tool_slug` values may be used by **gmail-lead-desk**. For any other Gmail tool, ask the user and default to **refuse** unless they explicitly need advanced mailbox admin.

**Schema:** `GET https://api.aisa.one/apis/v1/composio/tools/{tool_slug}`  
**Execute:** `POST https://api.aisa.one/apis/v1/composio/tools/execute/{tool_slug}` — see [`connect_and_execute.md`](./connect_and_execute.md).

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/tool_whitelist.md (reported line 6)May include surrounding context.

md
Only these `tool_slug` values may be used by **gmail-lead-desk**. For any other Gmail tool, ask the user and default to **refuse** unless they explicitly need advanced mailbox admin.

**Schema:** `GET https://api.aisa.one/apis/v1/composio/tools/{tool_slug}`  
**Execute:** `POST https://api.aisa.one/apis/v1/composio/tools/execute/{tool_slug}` — see [`connect_and_execute.md`](./connect_and_execute.md).

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/workflows.md (reported line 12)May include surrounding context.

md
Only these `tool_slug` values may be used by **gmail-lead-desk**. For any other Gmail tool, ask the user and default to **refuse** unless they explicitly need advanced mailbox admin.

**Schema:** `GET https://api.aisa.one/apis/v1/composio/tools/{tool_slug}`  
**Execute:** `POST https://api.aisa.one/apis/v1/composio/tools/execute/{tool_slug}` — see [`connect_and_execute.md`](./connect_and_execute.md).

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/workflows.md (reported line 33)May include surrounding context.

md
Only these `tool_slug` values may be used by **gmail-lead-desk**. For any other Gmail tool, ask the user and default to **refuse** unless they explicitly need advanced mailbox admin.

**Schema:** `GET https://api.aisa.one/apis/v1/composio/tools/{tool_slug}`  
**Execute:** `POST https://api.aisa.one/apis/v1/composio/tools/execute/{tool_slug}` — see [`connect_and_execute.md`](./connect_and_execute.md).

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/workflows.md (reported line 57)May include surrounding context.

md
Only these `tool_slug` values may be used by **gmail-lead-desk**. For any other Gmail tool, ask the user and default to **refuse** unless they explicitly need advanced mailbox admin.

**Schema:** `GET https://api.aisa.one/apis/v1/composio/tools/{tool_slug}`  
**Execute:** `POST https://api.aisa.one/apis/v1/composio/tools/execute/{tool_slug}` — see [`connect_and_execute.md`](./connect_and_execute.md).

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/workflows.md (reported line 82)May include surrounding context.

md
Only these `tool_slug` values may be used by **gmail-lead-desk**. For any other Gmail tool, ask the user and default to **refuse** unless they explicitly need advanced mailbox admin.

**Schema:** `GET https://api.aisa.one/apis/v1/composio/tools/{tool_slug}`  
**Execute:** `POST https://api.aisa.one/apis/v1/composio/tools/execute/{tool_slug}` — see [`connect_and_execute.md`](./connect_and_execute.md).

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/workflows.md (reported line 115)May include surrounding context.

md
Only these `tool_slug` values may be used by **gmail-lead-desk**. For any other Gmail tool, ask the user and default to **refuse** unless they explicitly need advanced mailbox admin.

**Schema:** `GET https://api.aisa.one/apis/v1/composio/tools/{tool_slug}`  
**Execute:** `POST https://api.aisa.one/apis/v1/composio/tools/execute/{tool_slug}` — see [`connect_and_execute.md`](./connect_and_execute.md).

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/workflows.md (reported line 165)May include surrounding context.

md
Only these `tool_slug` values may be used by **gmail-lead-desk**. For any other Gmail tool, ask the user and default to **refuse** unless they explicitly need advanced mailbox admin.

**Schema:** `GET https://api.aisa.one/apis/v1/composio/tools/{tool_slug}`  
**Execute:** `POST https://api.aisa.one/apis/v1/composio/tools/execute/{tool_slug}` — see [`connect_and_execute.md`](./connect_and_execute.md).

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/workflows.md (reported line 208)May include surrounding context.

md
Only these `tool_slug` values may be used by **gmail-lead-desk**. For any other Gmail tool, ask the user and default to **refuse** unless they explicitly need advanced mailbox admin.

**Schema:** `GET https://api.aisa.one/apis/v1/composio/tools/{tool_slug}`  
**Execute:** `POST https://api.aisa.one/apis/v1/composio/tools/execute/{tool_slug}` — see [`connect_and_execute.md`](./connect_and_execute.md).

---

Static analysis

No suspicious patterns detected.