gogcli-ops
Warn
Audited by Snyk on Mar 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly reads and fetches user-generated Google Workspace content (e.g., SKILL.md sections and commands like
gog docs cat <docId>,gog sheets get <spreadsheetId> <range>, andgog drive download <fileId>) which are untrusted third‑party sources and are consumed as part of the workflow, so their contents could indirectly influence subsequent actions.
Audit Metadata