recipe-backup-sheet-as-csv

Pass

Audited by Gen Agent Trust Hub on Mar 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the vendor's own 'gws' command-line interface to interact with Google Sheets and Google Drive APIs. This is standard behavior for a skill authored by googleworkspace.- [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection because it reads and exports content from external spreadsheets. * Ingestion points: Data is pulled from Google Sheets via 'gws drive files export' and 'gws sheets +read' as described in SKILL.md. * Boundary markers: There are no explicit delimiters or safety instructions provided to the agent regarding the content of the spreadsheet. * Capability inventory: The agent is granted the ability to read and export data from the user's Google Workspace environment. * Sanitization: The skill does not include steps to sanitize or validate the spreadsheet content.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 4, 2026, 10:49 PM