skills/ma1orek/replay/google-chat-api/Gen Agent Trust Hub

google-chat-api

Pass

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows security best practices by providing templates for production-ready bearer token verification using the Web Crypto API and fetching public keys from official Google services.\n- [EXTERNAL_DOWNLOADS]: Fetches public keys from Google's official service account endpoint (googleapis.com) to verify token signatures. This is a standard security procedure for validating identity in Google Workspace integrations and targets a well-known service.\n- [COMMAND_EXECUTION]: No suspicious shell command execution, privilege escalation, or persistence mechanisms were found. The skill relies on standard web technologies (Fetch API, TypeScript) within the Cloudflare Workers environment.\n- [PROMPT_INJECTION]: Instructions focus on API integration and card schema design without any attempts to bypass model safety filters or override system instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 25, 2026, 08:58 PM
Security Audit — agent-trust-hub — google-chat-api