gogcli
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill allows the agent to ingest untrusted data from Google Workspace services and perform high-privilege actions based on that data.
- Ingestion points: In
SKILL.md, the agent is instructed to read email bodies (gog gmail messages search --include-body), document content (gog docs cat), spreadsheet data (gog sheets get), and chat messages (gog chat messages list). - Boundary markers: The instructions do not define boundary markers or explicit instructions to the agent to ignore instructions found within the retrieved content.
- Capability inventory: The agent has wide-ranging capabilities across multiple files and scripts, including sending emails (
gog gmail send), creating calendar events (gog calendar create), uploading files (gog drive upload), and sending chat messages (gog chat dm send). - Sanitization: No sanitization or validation mechanisms are described for the external content before it is processed.
- [COMMAND_EXECUTION]: The skill is centered around the execution of the
gogcommand-line tool in a shell environment. - Evidence:
SKILL.mdcontains numerous examples of shell commands involving thegogutility and environment variable exports used to interact with Gmail, Calendar, Drive, and other Workspace services.
Audit Metadata