Research Google Workspace Integration

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, command injections, or persistence mechanisms were detected in the skill instructions or workflows.
  • [DATA_EXFILTRATION]: The skill is designed to interact with sensitive data from Gmail, Google Calendar, and Google Drive. This access is the primary intended purpose of the skill for research tasks and utilizes authorized tools with the mcp__google-workspace-mpm__ prefix. The documentation includes guidelines to respect user privacy and only access data relevant to the task. No patterns suggesting unauthorized data exfiltration were found.
  • [PROMPT_INJECTION]: The skill processes untrusted external data (emails and documents), which creates a surface for indirect prompt injection.
  • Ingestion points: External data is ingested via Gmail and Drive content retrieval tools (SKILL.md).
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions for processed data.
  • Capability inventory: The skill has access to workspace tools, codebase grep, and web search tools.
  • Sanitization: No specific sanitization or validation logic is defined for the external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 10:03 AM
Security Audit — agent-trust-hub — Research Google Workspace Integration