gdrive

Fail

Audited by Snyk on Feb 17, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). These are legitimate Google Docs/Drive URLs (widely used and not malicious by themselves) but Google Drive/personal file-hosting links are commonly abused to distribute executables and hide malware, so any download/execution from such links should be treated as potentially risky.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill can fetch and open arbitrary external content — e.g., "gog open " and "gog drive download " / "gog drive search" which retrieve user-generated or publicly shared Google Drive files and arbitrary URLs — exposing the agent to untrusted third-party content that could carry indirect prompt injections.
Audit Metadata
Risk Level
CRITICAL
Analyzed
Feb 17, 2026, 08:56 PM