managing-google-workspace

Warn

Audited by Snyk on May 13, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill exposes the agent to open web and arbitrary URL content (see references/search.md's search_custom for web search and references/drive.md + references/docs.md which allow importing or fetching files/images from arbitrary http/https URLs via import_to_google_doc, create_drive_file.fileUrl, and insert_doc_image), and those fetched, untrusted third-party contents are read and used by the agent as part of workflows, so they could carry indirect prompt-injection instructions that influence subsequent tool calls.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 13, 2026, 11:47 AM
Issues
1
Security Audit — snyk — managing-google-workspace