gws-chat

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates communication with the Google Chat API by executing the gws command-line tool. It includes methods for space management, message handling, and media uploads/downloads.
  • [PROMPT_INJECTION]: The skill processes external data from Google Chat messages and space metadata, creating an indirect prompt injection surface.
  • Ingestion points: API outputs from space listing, message retrieval, and search operations in SKILL.md.
  • Boundary markers: None explicitly defined in this file; the skill refers to a global shared configuration file (../gws-shared/SKILL.md) for security rules.
  • Capability inventory: The skill possesses the ability to create, update, and delete spaces and messages via the gws CLI.
  • Sanitization: Not explicitly implemented within this instruction file.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 01:27 PM
Security Audit — agent-trust-hub — gws-chat