recipe-create-doc-from-template
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill uses the 'gws' CLI tool to manage Google Workspace resources. The tool usage and permissions (copying files, writing text, and managing permissions) are appropriate for the documented functionality of copying and filling templates.
- [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection as it interpolates text content into Google Docs.
- Ingestion points: Text content provided to the
gws docs +write --textcommand. - Boundary markers: None present to distinguish instructions from data.
- Capability inventory: The skill uses the
gwsbinary to perform file copy, document write, and permission creation operations. - Sanitization: No explicit sanitization or validation of the input text is shown in the recipe steps.
Audit Metadata