google-drive-automation

Pass

Audited by Gen Agent Trust Hub on Mar 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires connecting to an external MCP server at https://rube.app/mcp to fetch tool schemas and perform operations. This is the official endpoint for the Rube/Composio toolkit used in the skill.\n- [PROMPT_INJECTION]: The skill handles external data from Google Drive, creating a potential surface for indirect prompt injection.\n
  • Ingestion points: Reads file content via GOOGLEDRIVE_DOWNLOAD_FILE and metadata via GOOGLEDRIVE_FIND_FILE.\n
  • Boundary markers: Absent. The instructions do not specify any delimiters or warnings to the agent regarding instructions embedded within the files it processes.\n
  • Capability inventory: Possesses significant capabilities including file uploads, folder management, and permission modification (GOOGLEDRIVE_ADD_FILE_SHARING_PREFERENCE).\n
  • Sanitization: Absent. No explicit sanitization or validation of content from external files is described in the prompt.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 13, 2026, 06:59 AM