gdrive-access
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted filenames, metadata, and file contents from the Google Drive API. It includes a specific instruction block labeled 'Self-Evolving Skill' that encourages the AI agent to rewrite the skill's instructions based on runtime experiences. This creates a feedback loop where malicious content retrieved from Google Drive could potentially influence the agent to modify its own logic or instructions.
- Ingestion points: Functions such as
listFiles,searchFiles, anddownloadFileinscripts/lib/drive.tsprocess data returned from external Google Drive API calls. - Boundary markers: The skill does not employ delimiters or specific instructions to the agent to disregard commands or instructions that might be embedded in the data retrieved from Drive.
- Capability inventory: The skill possesses the ability to execute shell commands (via 1Password CLI and browser spawning), write to the local file system (token storage and file downloads), and perform network operations.
- Sanitization: No explicit sanitization or validation of external metadata (e.g., file names) is performed before these strings are used in operations.
- [COMMAND_EXECUTION]: The skill executes the
op(1Password) CLI to retrieve OAuth secrets and uses the system'sopencommand to initiate browser-based authorization. These executions are legitimate and necessary for the tool's defined purpose of managing authenticated Google Drive access.
Audit Metadata