gws-docs

Pass

Audited by Gen Agent Trust Hub on Mar 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests content from external Google Documents, creating an opportunity for indirect prompt injection attack vectors.\n
  • Ingestion points: Data is retrieved from external documents using the get method as documented in SKILL.md.\n
  • Boundary markers: The skill does not implement boundary markers or instructions to treat ingested document content as untrusted data.\n
  • Capability inventory: The skill possesses significant capabilities to modify the environment, including batchUpdate, create, and the +write helper function in SKILL.md.\n
  • Sanitization: No sanitization or validation logic is present for the data retrieved from external Google Documents before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 20, 2026, 04:56 PM