gws-workspace

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of the Bash tool to execute gws CLI commands. These commands are used to interact with Google Workspace APIs for file management, spreadsheet operations, and email communication.
  • [EXTERNAL_DOWNLOADS]: The instructions recommend installing the @googleworkspace/cli package via the npm registry. This package is an established tool for Google Workspace developers and is hosted on a well-known service.
  • [DATA_EXFILTRATION]: The skill's primary function involves reading and exporting sensitive user data from Google Drive, Sheets, and Gmail. While this involves data movement, it is the intended and documented purpose of the toolset.
  • [PROMPT_INJECTION]: An indirect prompt injection surface is present because the skill processes data from untrusted external sources such as email bodies and document content.
  • Ingestion points: Untrusted data enters the context through commands like gws gmail users messages list and gws drive files get as seen in SKILL.md.
  • Boundary markers: The skill does not define specific delimiters to isolate external data from the agent's instructions when the data is retrieved.
  • Capability inventory: The agent has access to powerful tools including Bash, Write, and AskUserQuestion across the skill's reference files.
  • Sanitization: The risk is mitigated by explicit instructions to use the --sanitize flag for Model Armor screening and the requirement for user approval before performing any write or delete operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 05:08 PM
Security Audit — agent-trust-hub — gws-workspace