recipe-log-deal-update
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill reads content from external Google Sheets using the
gws sheets +readcommand. This data is untrusted and could contain malicious instructions designed to influence the agent's behavior during task execution. - [COMMAND_EXECUTION]: The skill executes shell commands via the
gwsCLI to interact with Google Drive and Sheets APIs. These tools are part of the Google Workspace vendor resource set and are used for the skill's primary purpose.
Audit Metadata