gog-workspace

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially malicious content from external sources including Gmail messages, Google Drive files, and Google Docs.
  • Ingestion points: os.shell.run calls to the gog CLI for Gmail search/get, Drive inventory/get, and Docs/Sheets reading.
  • Boundary markers: The skill templates in SKILL.md mandate the use of the --wrap-untrusted flag for all read operations.
  • Capability inventory: os.shell.run allows execution of the gog tool; write operations (sending email, deleting files) are restricted by instructions requiring explicit user approval and the use of the --gmail-no-send flag by default.
  • Sanitization: Instructions explicitly direct the agent to treat fetched content as untrusted input and use flags like --sanitize-content and --wrap-untrusted to prevent the agent from obeying instructions embedded in the data.
  • [COMMAND_EXECUTION]: The skill relies on os.shell.run to interface with the gog CLI. It defines strict command shapes to limit the arguments passed to the shell.
  • [EXTERNAL_DOWNLOADS]: The skill depends on the external gog CLI tool (hosted at github.com/openclaw/gogcli). While the skill includes scripts to check for its presence, installation and authentication are designated as manual human-in-the-loop processes to avoid automated credential handling.
  • [PRIVILEGE_ESCALATION]: Documentation for manual setup includes instructions to run PowerShell with -ExecutionPolicy Bypass. While this is a common practice for script execution on Windows, it is correctly scoped to a manual user setup step rather than an automated agent action.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 05:53 PM
Security Audit — agent-trust-hub — gog-workspace