gdrive-access

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted filenames, metadata, and file contents from the Google Drive API. It includes a specific instruction block labeled 'Self-Evolving Skill' that encourages the AI agent to rewrite the skill's instructions based on runtime experiences. This creates a feedback loop where malicious content retrieved from Google Drive could potentially influence the agent to modify its own logic or instructions.
  • Ingestion points: Functions such as listFiles, searchFiles, and downloadFile in scripts/lib/drive.ts process data returned from external Google Drive API calls.
  • Boundary markers: The skill does not employ delimiters or specific instructions to the agent to disregard commands or instructions that might be embedded in the data retrieved from Drive.
  • Capability inventory: The skill possesses the ability to execute shell commands (via 1Password CLI and browser spawning), write to the local file system (token storage and file downloads), and perform network operations.
  • Sanitization: No explicit sanitization or validation of external metadata (e.g., file names) is performed before these strings are used in operations.
  • [COMMAND_EXECUTION]: The skill executes the op (1Password) CLI to retrieve OAuth secrets and uses the system's open command to initiate browser-based authorization. These executions are legitimate and necessary for the tool's defined purpose of managing authenticated Google Drive access.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 12:42 PM
Security Audit — agent-trust-hub — gdrive-access