gog
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes untrusted data from Gmail, Google Drive, Docs, and Sheets, creating a surface for indirect prompt injection attacks.
- Ingestion points: Data is ingested via commands like
gog gmail search,gog drive search,gog sheets get, andgog docs catas described inSKILL.md. - Boundary markers: The instructions do not define specific delimiters or "ignore instructions" markers when handling content retrieved from these external sources.
- Capability inventory: The skill has the capability to perform high-impact actions including sending emails (
gog gmail send), modifying spreadsheets (gog sheets update), and creating calendar events (gog calendar create). - Sanitization: There is no evidence of content sanitization or validation before the retrieved data is processed or used in further actions.
- [COMMAND_EXECUTION]: The skill operates by executing shell commands via the
gogCLI tool. This involves passing user-supplied or externally-sourced arguments to the command line, which requires careful handling of parameters. - [CREDENTIALS_UNSAFE]: The skill's setup instructions reference the use of sensitive credential files, specifically mentioning a path to a
client_secret.jsonfile for OAuth authentication. While standard for this tool's operation, accessing such files is a sensitive action that requires user oversight.
Audit Metadata