gws-drive-upload

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the gws CLI tool to perform file uploads to Google Drive, which involves executing the command 'gws drive +upload' with user-specified arguments.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied file paths, establishing a potential surface for indirect prompt injection.
  • Ingestion points: The argument specified in the usage instructions of SKILL.md.
  • Boundary markers: No delimiters or boundary markers are present to wrap the input data.
  • Capability inventory: The skill is capable of file reading and network writing via the gws CLI.
  • Sanitization: No explicit input sanitization is present, although the skill includes a caution note requiring user confirmation before execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:04 AM
Security Audit — agent-trust-hub — gws-drive-upload