Back to skill

Security audit

Gmail

Security checks for vulnerabilities and agentic risk

Overview

This Gmail skill is purpose-aligned, but it asks users to connect a sensitive mailbox through an unpinned external plugin and does not clearly define confirmation or scope safeguards for sending and trashing mail.

Review this before installing. Only use it if you trust the MorphixAI plugin and understand that it can access Gmail content and perform state-changing actions such as sending mail, marking messages read, and moving messages to trash. Prefer a pinned or otherwise verified plugin version, check the Gmail scopes during account linking, and require preview/confirmation before sending or trashing messages.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:16
Finding

Unpinned Third-Party Plugin Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill exposes high-impact mailbox actions including reading message contents, sending mail, and trashing messages, but it does not present an explicit privacy, consent, or destructive-action warning to the user. In an agent context, this increases the risk of unintended disclosure of sensitive email data or unauthorized state-changing actions being taken without sufficient user awareness.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The natural-language content of the skill is presented only in Chinese, including the description and operating instructions. Under the language/locale policy, a skill should not force a specific language without user opt-in unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.