skills/deepgram/dglabs-deepclaw/gog/Gen Agent Trust Hub

gog

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires installing the gog CLI from a third-party Homebrew tap (steipete/tap/gogcli), which is not a verified vendor repository.\n- [DATA_EXFILTRATION]: Accesses sensitive user data from Gmail, Google Drive, Contacts, and Sheets. It also requires a client_secret.json file for authentication, which contains sensitive API credentials.\n- [COMMAND_EXECUTION]: Executes shell commands via the gog binary, passing data-derived arguments for various operations like sending emails and updating spreadsheets.\n- [PROMPT_INJECTION]:\n
  • Ingestion points: Content is ingested from Gmail, Drive, Sheets, and Docs via search and retrieval commands in SKILL.md.\n
  • Boundary markers: None. The skill does not instruct the agent to distinguish between its instructions and content retrieved from external sources.\n
  • Capability inventory: Includes high-impact capabilities like sending emails and modifying documents (gog gmail send, gog sheets update in SKILL.md).\n
  • Sanitization: None specified for external content retrieved through the CLI.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 09:14 PM
Security Audit — agent-trust-hub — gog