google-drive-comments

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill reads content from external Google Drive files, creating a potential surface for indirect prompt injection if the files contain malicious instructions.
  • Ingestion points: Data is ingested from document text, spreadsheet metadata, and presentation outlines (SKILL.md).
  • Boundary markers: No explicit boundary markers or isolation instructions are provided for document content.
  • Capability inventory: The agent can read metadata, search Drive, and perform bulk updates to comments.
  • Sanitization: The instructions do not mention sanitizing or filtering data from external files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 03:18 PM
Security Audit — agent-trust-hub — google-drive-comments