managing-google-workspace
Warn
Audited by Snyk on May 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill exposes the agent to open web and arbitrary URL content (see references/search.md's search_custom for web search and references/drive.md + references/docs.md which allow importing or fetching files/images from arbitrary http/https URLs via import_to_google_doc, create_drive_file.fileUrl, and insert_doc_image), and those fetched, untrusted third-party contents are read and used by the agent as part of workflows, so they could carry indirect prompt-injection instructions that influence subsequent tool calls.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata