google-docs-md
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses
curlto fetch content fromdocs.google.com. This involves well-known services and the downloads are part of the primary purpose of the skill. - [COMMAND_EXECUTION]: Provides bash snippets using standard tools like
grep,sort, andcurlto automate the extraction and downloading of documents. These commands are transparently documented. - [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest untrusted data from external Google Docs.
- Ingestion points: External content is pulled into the agent's context or file system via
curlfromdocs.google.com(seen inSKILL.md). - Boundary markers: The instructions do not define delimiters or warnings to ignore instructions found within the downloaded document content.
- Capability inventory: The skill uses
curlwhich has network and file-writing capabilities. - Sanitization: There is no mention of sanitizing, escaping, or validating the content of the Markdown file after it is downloaded.
Audit Metadata