gws-workspace
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of the
Bashtool to executegwsCLI commands. These commands are used to interact with Google Workspace APIs for file management, spreadsheet operations, and email communication. - [EXTERNAL_DOWNLOADS]: The instructions recommend installing the
@googleworkspace/clipackage via the npm registry. This package is an established tool for Google Workspace developers and is hosted on a well-known service. - [DATA_EXFILTRATION]: The skill's primary function involves reading and exporting sensitive user data from Google Drive, Sheets, and Gmail. While this involves data movement, it is the intended and documented purpose of the toolset.
- [PROMPT_INJECTION]: An indirect prompt injection surface is present because the skill processes data from untrusted external sources such as email bodies and document content.
- Ingestion points: Untrusted data enters the context through commands like
gws gmail users messages listandgws drive files getas seen inSKILL.md. - Boundary markers: The skill does not define specific delimiters to isolate external data from the agent's instructions when the data is retrieved.
- Capability inventory: The agent has access to powerful tools including
Bash,Write, andAskUserQuestionacross the skill's reference files. - Sanitization: The risk is mitigated by explicit instructions to use the
--sanitizeflag for Model Armor screening and the requirement for user approval before performing any write or delete operations.
Audit Metadata