recipe-bulk-download-folder
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides specific command-line templates for the
gwsbinary to perform operations like listing, downloading, and exporting files from Google Drive.\n- [PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection by retrieving data from an external source (Google Drive) that is not controlled by the skill itself.\n - Ingestion points: The skill uses
gws drive files listandgws drive files getto pull metadata and file content into the environment.\n - Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat the retrieved content as data rather than instructions.\n
- Capability inventory: The agent is equipped with the
gwsbinary, which allows for file system and network interactions.\n - Sanitization: The instructions do not include any steps for sanitizing or validating the files retrieved from Google Drive before they are processed by the agent.
Audit Metadata