skills/googleworkspace/cli/gws-events/Gen Agent Trust Hub

gws-events

Pass

Audited by Gen Agent Trust Hub on Mar 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill requires and executes the 'gws' binary, which is a vendor-owned resource for Google Workspace. This utility is used to interact with API resources like subscriptions, tasks, and operations.- [EXTERNAL_DOWNLOADS]: The skill references official Google developer documentation and API guides at 'developers.google.com'. These references target a well-known and trusted service.- [PROMPT_INJECTION]: The skill exposes ingestion points for external data through methods such as 'message.stream' and 'tasks.subscribe'. These streaming interfaces are designed to receive event data from Google Workspace. While this creates a surface for indirect prompt injection, it is the intended functionality of the skill and no vulnerabilities were found in the skill's structure. Evidence: Ingestion points found in SKILL.md (message.stream, tasks.subscribe); Capabilities include gws CLI execution; no specific boundary markers or sanitization logic is defined in the static markdown.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 5, 2026, 10:51 PM