google-workspace-ops

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect prompt injection attack surface identified. The skill requires the agent to read and process content from external sources such as Google Docs, Sheets, and Slides. \n
  • Ingestion points: Content is ingested from various Google Workspace assets during find and summarize operations (SKILL.md). \n
  • Boundary markers: The instructions lack explicit boundary markers or warnings to disregard instructions potentially embedded within the ingested documents. \n
  • Capability inventory: The agent is authorized to edit, rename, archive, and merge files across Google Drive. \n
  • Sanitization: No validation or sanitization of document content is specified before processing or acting upon the data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 12:58 PM
Security Audit — agent-trust-hub — google-workspace-ops