persona-it-admin
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill interacts with external, potentially untrusted data sources (emails, files, and audit logs) which could contain hidden malicious instructions.
- Ingestion points: Accesses information via gws-gmail, gws-drive, and gws-calendar utility skills as defined in the metadata and prerequisites (SKILL.md).
- Boundary markers: There are no explicit instructions or delimiters provided to prevent the agent from following instructions embedded within the processed emails or documents.
- Capability inventory: The skill utilizes the gws binary to perform administrative tasks, including configuring Drive sharing policies and reviewing security audit logs (SKILL.md).
- Sanitization: No sanitization or validation mechanisms are described for the content retrieved from the Workspace environment.
Audit Metadata