google-drive-comments
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- Indirect Prompt Injection Surface: The skill reads content from external Google Drive files, creating a potential surface for indirect prompt injection if the files contain malicious instructions.
- Ingestion points: Data is ingested from document text, spreadsheet metadata, and presentation outlines (SKILL.md).
- Boundary markers: No explicit boundary markers or isolation instructions are provided for document content.
- Capability inventory: The agent can read metadata, search Drive, and perform bulk updates to comments.
- Sanitization: The instructions do not mention sanitizing or filtering data from external files.
Audit Metadata