persona-project-manager
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external, potentially untrusted sources which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: The skill reads content from Gmail, Google Sheets, and Google Drive using the
gwsutility tools. - Boundary markers: The instructions lack explicit delimiters or guidance to treat content from external files or emails as untrusted data.
- Capability inventory: The persona has extensive write permissions, including sending emails via Gmail, appending data to Sheets, and uploading files to Drive.
- Sanitization: No sanitization, escaping, or validation logic is defined to handle external content before it is interpolated into workflows or actions.
Audit Metadata