google-workspace
Warn
Audited by Snyk on Apr 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The skill explicitly fetches and ingests user-generated third-party content from Google Drive/Docs/Sheets and Calendar (e.g., get_docs_content, read_sheets_data, list_drive_files, list_calendar_events), so untrusted document/spreadsheet/event text could be read and used to influence agent decisions and subsequent tool actions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata