gws-shared
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates interactions with external data sources like Google Drive and Google Sheets. Content from these services (such as file metadata or cell contents) enters the agent's context. While this creates a surface for indirect prompt injection, the skill specifically instructs the agent to use a
--sanitizeflag with Model Armor to screen for PII and content safety issues, and mandates user confirmation for write operations. - Ingestion points: Command outputs from the
gwsCLI (e.g.,gws drive files list). - Boundary markers: Not explicitly defined in the reference, but usage of the
--sanitizeflag is encouraged. - Capability inventory: File writing (
-o), file uploading (--upload), and general API interactions across Workspace services. - Sanitization: Instructions suggest using the
--sanitize <TEMPLATE>flag for safety screening. - [EXTERNAL_DOWNLOADS]: The documentation references the official project repository at
github.com/googleworkspace/clifor installation and community feedback. These references target the vendor's own official infrastructure.
Audit Metadata