gws-workflow
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill interfaces with external data sources that may contain malicious instructions.
- Ingestion points: Data enters via helper commands that read Gmail messages, Google Calendar events, and Google Drive files.
- Boundary markers: The skill lacks explicit markers or instructions to isolate untrusted content from the system prompt.
- Capability inventory: The skill uses the
gwscommand-line tool which has capabilities to read from and write to various Google Workspace services. - Sanitization: The provided instruction file does not include sanitization or validation logic for data retrieved from external sources.
Audit Metadata