google-drive
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted content from Google Drive files, which could contain instructions intended to manipulate the agent's behavior.
- Ingestion points: Untrusted data enters the agent context through the
read_filetool (which converts Docs, Sheets, and Slides to text),list_comments(which retrieves comment text and replies), andget_file_metadata. - Boundary markers: The skill instructions do not specify the use of delimiters or 'ignore' instructions to separate content retrieved from Drive from the agent's primary system instructions.
- Capability inventory: The skill includes powerful capabilities such as
share_file(granting access to emails),trash_file(deleting files/folders), and various creation/modification tools (create_file,update_file_content) across the Drive, Docs, and Sheets APIs. - Sanitization: No evidence of sanitization, validation, or filtering of external document content is mentioned before the data is processed by the agent.
Audit Metadata