google-workspace
Pass
Audited by Gen Agent Trust Hub on May 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect prompt injection vulnerability surface detected.\n- Ingestion point: Document content retrieved via
gws docs documents getinSKILL.md.\n- Boundary markers: No explicit markers or instructions to isolate document content from instructions.\n- Capability inventory: Subprocess execution ofgwsfor reading and writing documents across Google Workspace.\n- Sanitization:scripts/extract-doc-text.pyextracts raw text without filtering for instruction-like patterns.\n- Note: This finding is considered a risk surface inherent to the skill's primary document processing function.
Audit Metadata