google-contacts
Pass
Audited by Gen Agent Trust Hub on Oct 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill implements legitimate functionality to search and retrieve Google Contacts using the People API. No evidence of malicious code, unauthorized data exfiltration, or obfuscation was found.\n- [INDIRECT_PROMPT_INJECTION]: The skill has a data ingestion surface through contact information retrieved from an external API.\n
- Ingestion points: Contact data is ingested in handler.ts through the search_contacts and get_contact tools.\n
- Boundary markers: The contact information is returned as a formatted list without explicit delimiters or instructions to ignore embedded content.\n
- Capability inventory: The skill handler is limited to querying the Google People API and formatting results; it does not have access to shell commands, file system writes, or arbitrary network access.\n
- Sanitization: No sanitization is performed on the contact fields before they are returned to the agent context.
Audit Metadata