google-drive-automation

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill provides clear and legitimate instructions for interacting with Google Drive via a third-party tool provider.
  • [EXTERNAL_DOWNLOADS]: The skill references documentation and configuration endpoints from composio.dev and rube.app. These are well-known services for AI agent toolkits and are documented here neutrally as part of the setup process.
  • [DATA_EXFILTRATION]: While the skill manages data movement (uploads/downloads), it explicitly instructs the user to perform OAuth authentication via RUBE_MANAGE_CONNECTIONS, ensuring operations occur within the user's authorized context.
  • [INDIRECT_PROMPT_INJECTION]: As a tool for processing external files and search results, the skill possesses an inherent surface for indirect prompt injection. However, this is part of its primary function (file automation), and no malicious patterns are present in the instructions themselves.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 04:24 PM
Security Audit — agent-trust-hub — google-drive-automation