google-docs
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes processes for reading content from external documents via tools like
read_documentandgoogle_drive_read_file. This ingestion of untrusted data creates a surface where malicious instructions embedded within a document could potentially influence the agent's behavior. - Ingestion points: Tools
read_document,google_drive_read_file, andgoogle_drive_export_filedescribed inSKILL.mdare used to pull external document content into the agent's context. - Boundary markers: The instructions do not mention the use of delimiters or explicit warnings to the agent to ignore instructions found within the processed document text.
- Capability inventory: The skill has broad capabilities including creating documents (
create_document), inserting text and images, modifying styles, and performing bulk replacements or deletions. - Sanitization: There is no mention of content sanitization or validation before the agent acts on the information retrieved from the documents.
Audit Metadata