gtasks
Warn
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- Unverifiable Dependencies (MEDIUM): The skill depends on the
gogCLI (v0.10.0), which is not a standard system tool or a verified trusted dependency. This poses a potential risk as the source and security of the binary cannot be guaranteed. - Indirect Prompt Injection (LOW): The skill ingests data from Google Tasks, which could contain malicious payloads. \n
- Ingestion points: Task list and task detail output from
gog. \n - Boundary markers: Basic shell quoting is used, but no specific prompt delimiters are present. \n
- Capability inventory: Execution of the
gogbinary andjq. \n - Sanitization: No sanitization is applied to task content before it is processed by the agent.
Audit Metadata