gog-workspace
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially malicious content from external sources including Gmail messages, Google Drive files, and Google Docs.
- Ingestion points:
os.shell.runcalls to thegogCLI for Gmail search/get, Drive inventory/get, and Docs/Sheets reading. - Boundary markers: The skill templates in
SKILL.mdmandate the use of the--wrap-untrustedflag for all read operations. - Capability inventory:
os.shell.runallows execution of thegogtool; write operations (sending email, deleting files) are restricted by instructions requiring explicit user approval and the use of the--gmail-no-sendflag by default. - Sanitization: Instructions explicitly direct the agent to treat fetched content as untrusted input and use flags like
--sanitize-contentand--wrap-untrustedto prevent the agent from obeying instructions embedded in the data. - [COMMAND_EXECUTION]: The skill relies on
os.shell.runto interface with thegogCLI. It defines strict command shapes to limit the arguments passed to the shell. - [EXTERNAL_DOWNLOADS]: The skill depends on the external
gogCLI tool (hosted atgithub.com/openclaw/gogcli). While the skill includes scripts to check for its presence, installation and authentication are designated as manual human-in-the-loop processes to avoid automated credential handling. - [PRIVILEGE_ESCALATION]: Documentation for manual setup includes instructions to run PowerShell with
-ExecutionPolicy Bypass. While this is a common practice for script execution on Windows, it is correctly scoped to a manual user setup step rather than an automated agent action.
Audit Metadata