google-workspace-cli
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from untrusted external sources including Gmail messages, Google Drive files, and Google Chat spaces. This creates a surface for indirect prompt injection where malicious instructions embedded in documents or emails could be executed by the agent.\n
- Ingestion points: Gmail message bodies, Google Drive file content, Google Sheets cells, and Google Chat messages.\n
- Boundary markers: The skill documentation highlights the use of
gws modelarmor-sanitize-promptandmodelarmor-sanitize-responseas sanitization mechanisms.\n - Capability inventory: The skill possesses extensive capabilities including reading/writing files, sending emails, and modifying administrative settings across the Workspace environment.\n
- Sanitization: Sanitization via Google Cloud's Model Armor is recommended but must be explicitly configured by the user.\n- [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the
@googleworkspace/clipackage via npm and provides alternative installation methods from GitHub releases and source repositories.\n - Evidence: Downloads components from
https://github.com/googleworkspace/cliand installs the@googleworkspace/clipackage from the npm registry.\n- [COMMAND_EXECUTION]: The skill relies on thegwscommand-line tool to perform all operations. The agent is instructed to construct and execute complex shell commands involving JSON payloads and file paths.\n- [CREDENTIALS_UNSAFE]: The skill documentation describes how to manage sensitive credentials, including OAuth access tokens and service account JSON files. It mentions mechanisms for exporting unmasked credentials and storing them in environment variables likeGOOGLE_WORKSPACE_CLI_TOKEN.
Audit Metadata