gog
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires installing the
gogCLI from a third-party Homebrew tap (steipete/tap/gogcli), which is not a verified vendor repository.\n- [DATA_EXFILTRATION]: Accesses sensitive user data from Gmail, Google Drive, Contacts, and Sheets. It also requires aclient_secret.jsonfile for authentication, which contains sensitive API credentials.\n- [COMMAND_EXECUTION]: Executes shell commands via thegogbinary, passing data-derived arguments for various operations like sending emails and updating spreadsheets.\n- [PROMPT_INJECTION]:\n - Ingestion points: Content is ingested from Gmail, Drive, Sheets, and Docs via search and retrieval commands in
SKILL.md.\n - Boundary markers: None. The skill does not instruct the agent to distinguish between its instructions and content retrieved from external sources.\n
- Capability inventory: Includes high-impact capabilities like sending emails and modifying documents (
gog gmail send,gog sheets updateinSKILL.md).\n - Sanitization: None specified for external content retrieved through the CLI.
Audit Metadata