gws-docs
Pass
Audited by Gen Agent Trust Hub on Mar 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill ingests content from external Google Documents, creating an opportunity for indirect prompt injection attack vectors.\n
- Ingestion points: Data is retrieved from external documents using the
getmethod as documented inSKILL.md.\n - Boundary markers: The skill does not implement boundary markers or instructions to treat ingested document content as untrusted data.\n
- Capability inventory: The skill possesses significant capabilities to modify the environment, including
batchUpdate,create, and the+writehelper function inSKILL.md.\n - Sanitization: No sanitization or validation logic is present for the data retrieved from external Google Documents before it is processed by the agent.
Audit Metadata