recipe-create-doc-from-template

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill uses the 'gws' CLI tool to manage Google Workspace resources. The tool usage and permissions (copying files, writing text, and managing permissions) are appropriate for the documented functionality of copying and filling templates.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection as it interpolates text content into Google Docs.
  • Ingestion points: Text content provided to the gws docs +write --text command.
  • Boundary markers: None present to distinguish instructions from data.
  • Capability inventory: The skill uses the gws binary to perform file copy, document write, and permission creation operations.
  • Sanitization: No explicit sanitization or validation of the input text is shown in the recipe steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:12 AM
Security Audit — agent-trust-hub — recipe-create-doc-from-template