recipe-bulk-download-folder

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides specific command-line templates for the gws binary to perform operations like listing, downloading, and exporting files from Google Drive.\n- [PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection by retrieving data from an external source (Google Drive) that is not controlled by the skill itself.\n
  • Ingestion points: The skill uses gws drive files list and gws drive files get to pull metadata and file content into the environment.\n
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the retrieved content as data rather than instructions.\n
  • Capability inventory: The agent is equipped with the gws binary, which allows for file system and network interactions.\n
  • Sanitization: The instructions do not include any steps for sanitizing or validating the files retrieved from Google Drive before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 01:27 PM
Security Audit — agent-trust-hub — recipe-bulk-download-folder