skills/googleworkspace/cli/gws-shared/Gen Agent Trust Hub

gws-shared

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates interactions with external data sources like Google Drive and Google Sheets. Content from these services (such as file metadata or cell contents) enters the agent's context. While this creates a surface for indirect prompt injection, the skill specifically instructs the agent to use a --sanitize flag with Model Armor to screen for PII and content safety issues, and mandates user confirmation for write operations.
  • Ingestion points: Command outputs from the gws CLI (e.g., gws drive files list).
  • Boundary markers: Not explicitly defined in the reference, but usage of the --sanitize flag is encouraged.
  • Capability inventory: File writing (-o), file uploading (--upload), and general API interactions across Workspace services.
  • Sanitization: Instructions suggest using the --sanitize <TEMPLATE> flag for safety screening.
  • [EXTERNAL_DOWNLOADS]: The documentation references the official project repository at github.com/googleworkspace/cli for installation and community feedback. These references target the vendor's own official infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:12 AM
Security Audit — agent-trust-hub — gws-shared