skills/openai/plugins/google-drive/Gen Agent Trust Hub

google-drive

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [Command Execution]: The skill instructions outline a process for downloading slide thumbnails to the /tmp/ directory using curl. This is a technical procedure intended to allow the agent to visually inspect slide updates, ensuring that chart refreshes and layout adjustments are correctly rendered. This follows common patterns for agents performing visual verification tasks.
  • [Indirect Prompt Injection]: The skill processes data from external documents stored in Google Drive. This represents a potential surface for indirect prompt injection, where instructions embedded within the processed files could attempt to influence the agent's behavior. This is a standard characteristic of skills that interact with external content and is generally mitigated by the underlying model's safety guardrails.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 11:38 AM
Security Audit — agent-trust-hub — google-drive