Gws Admin

Security checks across malware telemetry and agentic risk

Overview

This skill is a Google Workspace admin command catalog, but it exposes powerful account, device, domain, and privilege-changing actions without enough visible safeguards.

Install only if you intentionally want an agent to administer Google Workspace. Before using it, inspect the gws CLI and the referenced gws-shared skill, use the narrowest possible admin/OAuth permissions, and require explicit human confirmation for any command that deletes, wipes, updates, revokes, turns off security features, or changes administrator privileges.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
81% confidence
Finding
The skill exposes numerous destructive and privilege-altering administrative operations such as deleting users, deleting groups, wiping devices, turning off 2-Step Verification, making users admins, and revoking tokens, but it does not consistently frame them with safety guardrails, confirmation requirements, or explicit risk warnings. In an agentic context, sparse warnings increase the chance of accidental misuse, overbroad execution, or unsafe automation against a highly privileged admin surface.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal