gws-chat-send

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the gws binary to send messages. This is the official command-line tool for Google Workspace services.
  • [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection as it handles external text input for transmission. 1. Ingestion points: The --text flag in SKILL.md. 2. Boundary markers: The skill includes a caution call-out requiring explicit user confirmation before execution. 3. Capability inventory: Executes the gws chat +send command as defined in SKILL.md. 4. Sanitization: Relies on the underlying CLI tool and the agent's internal safety guardrails.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:43 PM
Security Audit — agent-trust-hub — gws-chat-send