skills/openai/plugins/google-drive/Gen Agent Trust Hub

google-drive

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • Command Execution: The skill provides instructions for using the curl utility to download slide thumbnails to the local /tmp directory. This is used as a mechanism for visual verification during chart updates to ensure rendered layout consistency.\n- Indirect Prompt Injection Surface: The agent processes content from Google Drive documents, such as Docs, Sheets, and Slides, which may contain untrusted data or instructions. This represents a standard behavior for agents that read and summarize user documents.\n- Network Operations: The skill utilizes fetch and command-line tools to interact with Google Drive assets. These operations are directed at official service endpoints and are integral to the skill's file discovery and management capabilities.\n- Verification Standards: The skill includes robust verification loops for visual changes in presentations, requiring the agent to re-read slide structures and rendered thumbnails to confirm that automated edits meet quality standards.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 11:38 AM
Security Audit — agent-trust-hub — google-drive