google-docs

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the Membrane CLI (@membranehq/cli) from the official npm registry. This is a standard procedure for utilizing the vendor's provided tooling.
  • [COMMAND_EXECUTION]: The skill utilizes shell commands via the membrane CLI to perform authentication (membrane login), manage connections, and execute Google Docs actions. This is the primary mechanism for the skill's functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides an attack surface for indirect prompt injection as it ingests untrusted data from external Google Documents.
  • Ingestion points: Document content retrieved via get-document or action list results.
  • Boundary markers: None identified in the skill instructions to delimit external content from system instructions.
  • Capability inventory: The skill can execute shell commands (membrane CLI) and make network requests via a proxy (membrane request).
  • Sanitization: No explicit sanitization or validation of the document content is described, which is common for document processing integrations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 06:16 PM
Security Audit — agent-trust-hub — google-docs