Back to skill

Security audit

gmail

Security checks for vulnerabilities and agentic risk

Overview

This Gmail skill has sensitive email and automation capabilities, but the artifacts disclose them clearly and constrain them to user-approved Maton/Gmail workflows.

Install this only if you intend to let Maton access the selected Gmail account. Before approving writes, sending mail, creating automations, or adding trigger destinations, verify the exact account, recipient or URL, data fields, persistence, and cleanup plan. Prefer OAuth/CLI auth over raw API keys and avoid third-party destinations unless you explicitly trust the host and understand what mailbox data will flow there.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest says this skill is for Gmail API integration, while these lines describe Linear as an event source, including scoping, payload handling, and destination forwarding. Although the text tries to limit use to explicit user requests, embedding non-Gmail event-source capability in a Gmail skill is not justified by the skill's stated primary purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.