google-contacts

Pass

Audited by Gen Agent Trust Hub on Oct 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill implements legitimate functionality to search and retrieve Google Contacts using the People API. No evidence of malicious code, unauthorized data exfiltration, or obfuscation was found.\n- [INDIRECT_PROMPT_INJECTION]: The skill has a data ingestion surface through contact information retrieved from an external API.\n
  • Ingestion points: Contact data is ingested in handler.ts through the search_contacts and get_contact tools.\n
  • Boundary markers: The contact information is returned as a formatted list without explicit delimiters or instructions to ignore embedded content.\n
  • Capability inventory: The skill handler is limited to querying the Google People API and formatting results; it does not have access to shell commands, file system writes, or arbitrary network access.\n
  • Sanitization: No sanitization is performed on the contact fields before they are returned to the agent context.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 9, 2026, 08:42 AM