gtasks

Warn

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • Unverifiable Dependencies (MEDIUM): The skill depends on the gog CLI (v0.10.0), which is not a standard system tool or a verified trusted dependency. This poses a potential risk as the source and security of the binary cannot be guaranteed.
  • Indirect Prompt Injection (LOW): The skill ingests data from Google Tasks, which could contain malicious payloads. \n
  • Ingestion points: Task list and task detail output from gog. \n
  • Boundary markers: Basic shell quoting is used, but no specific prompt delimiters are present. \n
  • Capability inventory: Execution of the gog binary and jq. \n
  • Sanitization: No sanitization is applied to task content before it is processed by the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 17, 2026, 08:56 PM