Skip to content
Report library
Purpose / Writing

Persona Content Creator Skill Security Audit

What the author says it does (original text)

Create, organize, and distribute content across Workspace.

Independent security check

Do not install or run it yet

Files checked
1
Risks found
2
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.Risks found: 1
High risk

Content may be disclosed through Chat or Gmail without confirming recipients and sharing scope

Source references: 1
What we found

The instructions announce finished content in Chat and email review requests, but do not require confirmation of recipients, Chat space, attachments, or link permissions.

Why this matters

If the content contains unreleased material, customer information, or internal links, unintended recipients or space members could receive it or gain an access path.

What this evidence establishes

These are active instructions to distribute content through Google Chat and Gmail. If executed while the recipients, Chat space, or link permissions are unclear, content could reach the wrong people. However, the source names no recipient and does not direct the agent to bypass confirmation or broaden access; the actions match the stated distribution purpose. The shown lines do not establish whether the underlying workflows obtain and confirm targets from the user's request. A user can ask the author how recipients, spaces, and link permissions are presented for approval before sending.

This assessment concerns the code and conditions shown, not proof that harm has occurred.
SKILL.md:31In the instructionsOpen original file
- Organize content assets in Drive folders — use `gws drive files list` to browse.- Share finished content by announcing in Chat with `gws workflow +file-announce`.- Send content review requests via email with `gws gmail +send`.- Upload media assets to Drive with `gws drive +upload`.
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.Risks found: 1
Medium risk

Cloud content may be changed without confirming the destination document or folder

Source references: 2
What we found

The instructions directly call for writing Google Docs and uploading to Drive without requiring confirmation of the document, destination folder, overwrite behavior, or access settings.

Why this matters

The agent could alter the wrong shared document, place media in the wrong folder, or let a file inherit broader sharing than intended. These are persistent account changes.

What this evidence establishes

The skill explicitly writes to Google Docs and uploads files to Drive, so using it can change the user's cloud content. An ambiguous document or folder could cause a misplaced change, but the source does not instruct overwriting existing files, changing permissions, or independently choosing a target, and writing/organizing/uploading match its stated function. These lines do not show whether the commands require target parameters or confirmation. A user can restrict it to explicitly named documents and folders and ask how upload conflicts and overwrites are handled.

This assessment concerns the code and conditions shown, not proof that harm has occurred.
SKILL.md:29In the instructionsOpen original file
## Instructions- Draft content in Google Docs with `gws docs +write`.- Organize content assets in Drive folders — use `gws drive files list` to browse.- Share finished content by announcing in Chat with `gws workflow +file-announce`.
Show 1 other places
SKILL.md:33In the instructionsOpen original file
- Send content review requests via email with `gws gmail +send`.- Upload media assets to Drive with `gws drive +upload`.
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.No risks found
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.No risks found
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.No risks found

Inside this skill

3 instruction sections

This Skill is a Google Workspace content-publishing workflow: it creates or updates Docs, browses and uploads Drive files, and distributes content through Chat and Gmail.

View source
SKILL.md:29In the instructionsOpen original file
## Instructions- Draft content in Google Docs with `gws docs +write`.- Organize content assets in Drive folders — use `gws drive files list` to browse.- Share finished content by announcing in Chat with `gws workflow +file-announce`.- Send content review requests via email with `gws gmail +send`.- Upload media assets to Drive with `gws drive +upload`.

Operating the persona requires loading five Workspace tool capabilities, including Gmail, Chat, Drive, Docs, and Slides; the effective permissions still depend on those dependencies and the user's account authorization.

View source
SKILL.md:8In the instructionsOpen original file
    category: "persona"    requires:      bins:        - gws      skills:        - gws-docs        - gws-drive        - gws-gmail        - gws-chat        - gws-slides---
SKILL.md:21In the instructionsOpen original file
> **PREREQUISITE:** Load the following utility skills to operate as this persona: `gws-docs`, `gws-drive`, `gws-gmail`, `gws-chat`, `gws-slides`
Start here · InstructionsSKILL.md
persona-content-creator
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source.
Files and check records1 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions
Lines read
40
File checksum (to compare versions)
dfd82763b5f0bc3a1df0e317d89fd9811e3e73478d82222a186be6981acfd613