Back to skill

Security audit

gmail-memory

Security checks for vulnerabilities and agentic risk

Overview

This Gmail memory skill does what it claims, but it can automatically send and persist email-thread summaries in an external BlueColumn service without enough consent, redaction, or deletion guidance.

Review carefully before installing. Only use this skill if you trust BlueColumn with Gmail-derived summaries, have approval to send that email context to an external memory service, and are prepared to manually redact secrets, personal data, financial terms, and confidential thread details before storage.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:9
Finding

Automatic External Persistence of Potentially Sensitive Gmail Context Without Explicit Consent or Redaction

Content
View full analysis
" \ -H "Content-Type: application/json" \ -d '{"text": "Thread w/ vendor: quote sent 7/28, awaiting PO.", "title": "gmail-memory - note"}' ``` ## Quick note ```bash curl -X POST .../agent-note \ -H "Authorization: Bearer " \ -H "Content-Type: application/json" \ -d '{"text": "Thread w/ vendor: quote sent 7/28, awaiting PO.", "tags": ["gmail-memory"]}' ``` ## Recall ```bash curl -X POST .../agent-recall \ -H "Authorization: Bearer " \ -H "Content-Type: application/json" \ -d '{"q": "What's the latest in my thread with the vendor?"}' ``` ## Workflow 1. On new context, first recall: `What's the latest in my thread with the vendor?` 2. Use the answer to personalize the response 3. After the interaction, store the summary via `/agent-remember` ``` ### Technical Analysis The skill instructs the agent to retrieve a BlueColumn API credential from `TOOLS.md` or a platform secret store and use it to send Gmail-thread summaries to an external Supabase-hosted service. The workflow directs the agent to store a summary after the interaction without requiring explicit user approval for that transmission. Email threads can contain personal information, commercial terms, internal communications, access links, credentials, or other confidential material. The instructions provide no requirements for: - Obtaining informed consent before an external write. - Limiting storage to user-selected threads or fields. - Detecting and redacting credentials, tokens, personal data, or confidential con ...[truncated 2264 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly promotes storing Gmail thread context in an external persistent memory service, but it does not clearly warn that email content may leave the local/system boundary and be retained by a third party. Because Gmail threads often contain sensitive business or personal data, omission of consent, minimization, and privacy guidance creates a real risk of unintended data disclosure.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This is a true external-transmission finding: the skill instructs posting email-thread-derived text to a remote API endpoint. In this skill's context, external transmission is the core feature rather than inherently malicious behavior, but it still creates a meaningful confidentiality risk because Gmail thread contents may include sensitive or regulated information.

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

Store

bash
curl -X POST .../agent-remember \
  -H "Authorization: Bearer <key>" \
  -H "Content-Type: application/json" \
  -d '{"text": "Thread w/ vendor: quote sent 7/28, awaiting PO.", "title": "gmail-memory - note"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example commands send thread text directly to external endpoints using curl, normalizing off-system transmission of potentially sensitive email content without any warning or safeguards. This is dangerous because users or agents may copy the pattern verbatim and upload confidential thread details, vendor communications, or personal information to a third-party service unintentionally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.