google-workspace-ops
Pass
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect prompt injection attack surface identified. The skill requires the agent to read and process content from external sources such as Google Docs, Sheets, and Slides. \n
- Ingestion points: Content is ingested from various Google Workspace assets during find and summarize operations (SKILL.md). \n
- Boundary markers: The instructions lack explicit boundary markers or warnings to disregard instructions potentially embedded within the ingested documents. \n
- Capability inventory: The agent is authorized to edit, rename, archive, and merge files across Google Drive. \n
- Sanitization: No validation or sanitization of document content is specified before processing or acting upon the data.
Audit Metadata