{"data":{"skill":{"slug":"googleworkspace-gws-drive","name":"gws-drive","icon":"📦","repo":"https://github.com/googleworkspace/cli/tree/main/skills/gws-drive/","status":"approved","author":"googleworkspace","authorVersion":"0.23.0","skillstoreRevision":2},"audit":{"id":"53f46fcb-3fd2-44f8-9b24-da9bab529203","skill_id":"5c37078c-804d-434c-8adb-30caffeb4856","version":5,"content_hash":"v3:286d37c9c189ddd1aafd3548415fb031d1df79d5:ab6e66702196c465e1e58a7a9735b31687625079d4fbfa47d1835db26d9b1696:71ebeb163f29ccb8fc4f96e322e7d5432f7340056c161352caf3c635f41ca072:736b696c6c732f676f6f676c65776f726b73706163652f6777732d6472697665:77c99ee72ed88fd570c464699172dbb1","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 111 static findings are false positives caused by Markdown formatting, documentation links, relative sibling references, and Drive API method descriptions. No prompt injection or malicious behavior appears, but consequential Drive mutations need explicit confirmation.","remediation":[{"issue":"Consequential approval, deletion, update, and permission methods lack confirmation guidance in this file.","severity":"medium","suggestion":"Require a preview and explicit user confirmation before changing access, deleting content, resolving proposals, or replacing file data."},{"issue":"Authentication and security rules depend on a sibling skill referenced at runtime.","severity":"low","suggestion":"Package the shared guidance with this skill and stop execution when it cannot be loaded."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":16,"line_start":16},{"file":"SKILL.md","line_end":20,"line_start":18},{"file":"SKILL.md","line_end":26,"line_start":20},{"file":"SKILL.md","line_end":32,"line_start":26},{"file":"SKILL.md","line_end":32,"line_start":32},{"file":"SKILL.md","line_end":37,"line_start":36},{"file":"SKILL.md","line_end":38,"line_start":37},{"file":"SKILL.md","line_end":42,"line_start":38},{"file":"SKILL.md","line_end":43,"line_start":42},{"file":"SKILL.md","line_end":47,"line_start":43},{"file":"SKILL.md","line_end":48,"line_start":47},{"file":"SKILL.md","line_end":52,"line_start":48},{"file":"SKILL.md","line_end":53,"line_start":52},{"file":"SKILL.md","line_end":54,"line_start":53},{"file":"SKILL.md","line_end":58,"line_start":54},{"file":"SKILL.md","line_end":62,"line_start":58},{"file":"SKILL.md","line_end":62,"line_start":62},{"file":"SKILL.md","line_end":64,"line_start":63},{"file":"SKILL.md","line_end":64,"line_start":64},{"file":"SKILL.md","line_end":65,"line_start":65},{"file":"SKILL.md","line_end":66,"line_start":66},{"file":"SKILL.md","line_end":71,"line_start":70},{"file":"SKILL.md","line_end":72,"line_start":71},{"file":"SKILL.md","line_end":73,"line_start":72},{"file":"SKILL.md","line_end":73,"line_start":73},{"file":"SKILL.md","line_end":75,"line_start":74},{"file":"SKILL.md","line_end":79,"line_start":75},{"file":"SKILL.md","line_end":80,"line_start":79},{"file":"SKILL.md","line_end":80,"line_start":80},{"file":"SKILL.md","line_end":82,"line_start":81},{"file":"SKILL.md","line_end":83,"line_start":82},{"file":"SKILL.md","line_end":84,"line_start":83},{"file":"SKILL.md","line_end":84,"line_start":84},{"file":"SKILL.md","line_end":85,"line_start":85},{"file":"SKILL.md","line_end":87,"line_start":86},{"file":"SKILL.md","line_end":88,"line_start":87},{"file":"SKILL.md","line_end":88,"line_start":88},{"file":"SKILL.md","line_end":93,"line_start":89},{"file":"SKILL.md","line_end":97,"line_start":93},{"file":"SKILL.md","line_end":98,"line_start":97},{"file":"SKILL.md","line_end":99,"line_start":98},{"file":"SKILL.md","line_end":100,"line_start":99},{"file":"SKILL.md","line_end":101,"line_start":100},{"file":"SKILL.md","line_end":105,"line_start":101},{"file":"SKILL.md","line_end":106,"line_start":105},{"file":"SKILL.md","line_end":107,"line_start":106},{"file":"SKILL.md","line_end":108,"line_start":107},{"file":"SKILL.md","line_end":109,"line_start":108},{"file":"SKILL.md","line_end":113,"line_start":109},{"file":"SKILL.md","line_end":114,"line_start":113}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":83,"line_start":83},{"file":"SKILL.md","line_end":32,"line_start":32},{"file":"SKILL.md","line_end":36,"line_start":36},{"file":"SKILL.md","line_end":37,"line_start":37},{"file":"SKILL.md","line_end":38,"line_start":38},{"file":"SKILL.md","line_end":47,"line_start":47},{"file":"SKILL.md","line_end":48,"line_start":48},{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":53,"line_start":53},{"file":"SKILL.md","line_end":54,"line_start":54},{"file":"SKILL.md","line_end":58,"line_start":58},{"file":"SKILL.md","line_end":62,"line_start":62},{"file":"SKILL.md","line_end":63,"line_start":63},{"file":"SKILL.md","line_end":64,"line_start":64},{"file":"SKILL.md","line_end":65,"line_start":65},{"file":"SKILL.md","line_end":66,"line_start":66},{"file":"SKILL.md","line_end":70,"line_start":70},{"file":"SKILL.md","line_end":71,"line_start":71},{"file":"SKILL.md","line_end":72,"line_start":72},{"file":"SKILL.md","line_end":73,"line_start":73},{"file":"SKILL.md","line_end":74,"line_start":74},{"file":"SKILL.md","line_end":75,"line_start":75},{"file":"SKILL.md","line_end":79,"line_start":79},{"file":"SKILL.md","line_end":80,"line_start":80},{"file":"SKILL.md","line_end":81,"line_start":81},{"file":"SKILL.md","line_end":82,"line_start":82},{"file":"SKILL.md","line_end":83,"line_start":83},{"file":"SKILL.md","line_end":84,"line_start":84},{"file":"SKILL.md","line_end":85,"line_start":85},{"file":"SKILL.md","line_end":86,"line_start":86},{"file":"SKILL.md","line_end":87,"line_start":87},{"file":"SKILL.md","line_end":89,"line_start":89},{"file":"SKILL.md","line_end":97,"line_start":97},{"file":"SKILL.md","line_end":98,"line_start":98},{"file":"SKILL.md","line_end":99,"line_start":99},{"file":"SKILL.md","line_end":100,"line_start":100},{"file":"SKILL.md","line_end":101,"line_start":101},{"file":"SKILL.md","line_end":105,"line_start":105},{"file":"SKILL.md","line_end":106,"line_start":106},{"file":"SKILL.md","line_end":107,"line_start":107},{"file":"SKILL.md","line_end":108,"line_start":108},{"file":"SKILL.md","line_end":109,"line_start":109},{"file":"SKILL.md","line_end":113,"line_start":113},{"file":"SKILL.md","line_end":114,"line_start":114},{"file":"SKILL.md","line_end":115,"line_start":115},{"file":"SKILL.md","line_end":116,"line_start":116}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":16,"line_start":16},{"file":"SKILL.md","line_end":26,"line_start":26}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Consequential Drive Operations Need Confirmation","locations":[{"file":"SKILL.md","line_end":16,"line_start":16},{"file":"SKILL.md","line_end":38,"line_start":38},{"file":"SKILL.md","line_end":63,"line_start":63},{"file":"SKILL.md","line_end":88,"line_start":88},{"file":"SKILL.md","line_end":98,"line_start":98},{"file":"SKILL.md","line_end":101,"line_start":101},{"file":"SKILL.md","line_end":113,"line_start":113}],"confidence":0.95,"description":"The skill lists approval, deletion, file update, permission change, and revision deletion methods without local confirmation requirements. Broad requests could cause data loss or access changes.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The methods are explicitly documented at the cited lines. Confidence is slightly reduced because line 16 delegates security rules to a sibling skill."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":139,"audit_model":"codex","audited_at":"2026-08-05T10:55:05.197+00:00","created_at":"2026-08-06T01:08:37.006865+00:00","static_findings":[{"id":"external_commands:SKILL.md:16:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> **PREREQUISITE:** Read `../gws-shared/SKILL.md` for auth, global flags, and security rules. If mis","category":"external_commands","line_end":16,"severity":"medium","line_start":16},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":20,"severity":"medium","line_start":18},{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":26,"severity":"medium","line_start":20},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| [`+upload`](../gws-drive-upload/SKILL.md) | Upload a file with automatic metadata |","category":"external_commands","line_end":32,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `get` — Gets information about the user, the user's Drive, and system capabilities. For more infor","category":"external_commands","line_end":32,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `get` — Retrieves an access proposal by ID. For more information, see [Manage pending access propo","category":"external_commands","line_end":37,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `list` — List the access proposals on a file. For more information, see [Manage pending access pro","category":"external_commands","line_end":38,"severity":"medium","line_start":37},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `resolve` — Approves or denies an access proposal. For more information, see [Manage pending acces","category":"external_commands","line_end":42,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `get` — Gets an Approval by ID.","category":"external_commands","line_end":43,"severity":"medium","line_start":42},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `list` — Lists the Approvals on a file.","category":"external_commands","line_end":47,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `get` — Gets a specific app. For more information, see [Return user info](https://developers.googl","category":"external_commands","line_end":48,"severity":"medium","line_start":47},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `list` — Lists a user's installed apps. For more information, see [Return user info](https://devel","category":"external_commands","line_end":52,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `getStartPageToken` — Gets the starting pageToken for listing future changes. For more information","category":"external_commands","line_end":53,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `list` — Lists the changes for a user or shared drive. For more information, see [Retrieve changes","category":"external_commands","line_end":54,"severity":"medium","line_start":53},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `watch` — Subscribes to changes for a user. For more information, see [Notifications for resource ","category":"external_commands","line_end":58,"severity":"medium","line_start":54},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `stop` — Stops watching resources through this channel. For more information, see [Notifications f","category":"external_commands","line_end":62,"severity":"medium","line_start":58},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `create` — Creates a comment on a file. For more information, see [Manage comments and replies](ht","category":"external_commands","line_end":62,"severity":"medium","line_start":62},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `delete` — Deletes a comment. For more information, see [Manage comments and replies](https://deve","category":"external_commands","line_end":64,"severity":"medium","line_start":63},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `get` — Gets a comment by ID. For more information, see [Manage comments and replies](https://deve","category":"external_commands","line_end":64,"severity":"medium","line_start":64},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `list` — Lists a file's comments. For more information, see [Manage comments and replies](https://","category":"external_commands","line_end":65,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `update` — Updates a comment with patch semantics. For more information, see [Manage comments and ","category":"external_commands","line_end":66,"severity":"medium","line_start":66},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `create` — Creates a shared drive. For more information, see [Manage shared drives](https://develo","category":"external_commands","line_end":71,"severity":"medium","line_start":70},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `get` — Gets a shared drive's metadata by ID. For more information, see [Manage shared drives](htt","category":"external_commands","line_end":72,"severity":"medium","line_start":71},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `hide` — Hides a shared drive from the default view. For more information, see [Manage shared driv","category":"external_commands","line_end":73,"severity":"medium","line_start":72},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `list` — Lists the user's shared drives. This method accepts the `q` parameter, which is a search ","category":"external_commands","line_end":73,"severity":"medium","line_start":73},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `unhide` — Restores a shared drive to the default view. For more information, see [Manage shared d","category":"external_commands","line_end":75,"severity":"medium","line_start":74},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `update` — Updates the metadata for a shared drive. For more information, see [Manage shared drive","category":"external_commands","line_end":79,"severity":"medium","line_start":75},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `copy` — Creates a copy of a file and applies any requested updates with patch semantics. For more","category":"external_commands","line_end":80,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `create` — Creates a file. For more information, see [Create and manage files](https://developers.","category":"external_commands","line_end":80,"severity":"medium","line_start":80},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `download` — Downloads the content of a file. For more information, see [Download and export files","category":"external_commands","line_end":82,"severity":"medium","line_start":81},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `export` — Exports a Google Workspace document to the requested MIME type and returns exported byt","category":"external_commands","line_end":83,"severity":"medium","line_start":82},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `generateIds` — Generates a set of file IDs which can be provided in create or copy requests. For ","category":"external_commands","line_end":84,"severity":"medium","line_start":83},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `get` — Gets a file's metadata or content by ID. For more information, see [Search for files and f","category":"external_commands","line_end":84,"severity":"medium","line_start":84},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `list` — Lists the user's files. For more information, see [Search for files and folders](https://","category":"external_commands","line_end":85,"severity":"medium","line_start":85},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `listLabels` — Lists the labels on a file. For more information, see [List labels on a file](https","category":"external_commands","line_end":87,"severity":"medium","line_start":86},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `modifyLabels` — Modifies the set of labels applied to a file. For more information, see [Set a la","category":"external_commands","line_end":88,"severity":"medium","line_start":87},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `update` — Updates a file's metadata, content, or both. When calling this method, only populate fi","category":"external_commands","line_end":88,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `watch` — Subscribes to changes to a file. For more information, see [Notifications for resource c","category":"external_commands","line_end":93,"severity":"medium","line_start":89},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `get` — Gets the latest state of a long-running operation. Clients can use this method to poll the","category":"external_commands","line_end":97,"severity":"medium","line_start":93},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `create` — Creates a permission for a file or shared drive. For more information, see [Share files","category":"external_commands","line_end":98,"severity":"medium","line_start":97},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `delete` — Deletes a permission. For more information, see [Share files, folders, and drives](http","category":"external_commands","line_end":99,"severity":"medium","line_start":98},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `get` — Gets a permission by ID. For more information, see [Share files, folders, and drives](http","category":"external_commands","line_end":100,"severity":"medium","line_start":99},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `list` — Lists a file's or shared drive's permissions. For more information, see [Share files, fol","category":"external_commands","line_end":101,"severity":"medium","line_start":100},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `update` — Updates a permission with patch semantics. For more information, see [Share files, fold","category":"external_commands","line_end":105,"severity":"medium","line_start":101},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `create` — Creates a reply to a comment. For more information, see [Manage comments and replies](h","category":"external_commands","line_end":106,"severity":"medium","line_start":105},{"id":"external_commands:SKILL.md:106:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `delete` — Deletes a reply. For more information, see [Manage comments and replies](https://develo","category":"external_commands","line_end":107,"severity":"medium","line_start":106},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `get` — Gets a reply by ID. For more information, see [Manage comments and replies](https://develo","category":"external_commands","line_end":108,"severity":"medium","line_start":107},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `list` — Lists a comment's replies. For more information, see [Manage comments and replies](https:","category":"external_commands","line_end":109,"severity":"medium","line_start":108},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `update` — Updates a reply with patch semantics. For more information, see [Manage comments and re","category":"external_commands","line_end":113,"severity":"medium","line_start":109},{"id":"external_commands:SKILL.md:113:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `delete` — Permanently deletes a file version. You can only delete revisions for files with binary","category":"external_commands","line_end":114,"severity":"medium","line_start":113},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `get` — Gets a revision's metadata or content by ID. For more information, see [Manage file revisi","category":"external_commands","line_end":115,"severity":"medium","line_start":114},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `list` — Lists a file's revisions. For more information, see [Manage file revisions](https://devel","category":"external_commands","line_end":116,"severity":"medium","line_start":115},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `update` — Updates a revision with patch semantics. For more information, see [Manage file revisio","category":"external_commands","line_end":120,"severity":"medium","line_start":116},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `create` — Deprecated: Use `drives.create` instead.","category":"external_commands","line_end":120,"severity":"medium","line_start":120},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `get` — Deprecated: Use `drives.get` instead.","category":"external_commands","line_end":121,"severity":"medium","line_start":121},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `list` — Deprecated: Use `drives.list` instead.","category":"external_commands","line_end":122,"severity":"medium","line_start":122},{"id":"external_commands:SKILL.md:123:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `update` — Deprecated: Use `drives.update` instead.","category":"external_commands","line_end":123,"severity":"medium","line_start":123},{"id":"external_commands:SKILL.md:129:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":135,"severity":"medium","line_start":129},{"id":"external_commands:SKILL.md:135:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":137,"severity":"medium","line_start":135},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use `gws schema` output to build your `--params` and `--json` flags.","category":"external_commands","line_end":137,"severity":"medium","line_start":137},{"id":"network:SKILL.md:83:python-http-libraries","file":"SKILL.md","pattern":"Python HTTP libraries","snippet":"- `generateIds` — Generates a set of file IDs which can be provided in create or copy requests. For ","category":"network","line_end":83,"severity":"low","line_start":83},{"id":"network:SKILL.md:32:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `get` — Gets information about the user, the user's Drive, and system capabilities. For more infor","category":"network","line_end":32,"severity":"low","line_start":32},{"id":"network:SKILL.md:36:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `get` — Retrieves an access proposal by ID. For more information, see [Manage pending access propo","category":"network","line_end":36,"severity":"low","line_start":36},{"id":"network:SKILL.md:37:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `list` — List the access proposals on a file. For more information, see [Manage pending access pro","category":"network","line_end":37,"severity":"low","line_start":37},{"id":"network:SKILL.md:38:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `resolve` — Approves or denies an access proposal. For more information, see [Manage pending acces","category":"network","line_end":38,"severity":"low","line_start":38},{"id":"network:SKILL.md:47:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `get` — Gets a specific app. For more information, see [Return user info](https://developers.googl","category":"network","line_end":47,"severity":"low","line_start":47},{"id":"network:SKILL.md:48:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `list` — Lists a user's installed apps. For more information, see [Return user info](https://devel","category":"network","line_end":48,"severity":"low","line_start":48},{"id":"network:SKILL.md:52:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `getStartPageToken` — Gets the starting pageToken for listing future changes. For more information","category":"network","line_end":52,"severity":"low","line_start":52},{"id":"network:SKILL.md:53:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `list` — Lists the changes for a user or shared drive. For more information, see [Retrieve changes","category":"network","line_end":53,"severity":"low","line_start":53},{"id":"network:SKILL.md:54:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `watch` — Subscribes to changes for a user. For more information, see [Notifications for resource ","category":"network","line_end":54,"severity":"low","line_start":54},{"id":"network:SKILL.md:58:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `stop` — Stops watching resources through this channel. For more information, see [Notifications f","category":"network","line_end":58,"severity":"low","line_start":58},{"id":"network:SKILL.md:62:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `create` — Creates a comment on a file. For more information, see [Manage comments and replies](ht","category":"network","line_end":62,"severity":"low","line_start":62},{"id":"network:SKILL.md:63:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `delete` — Deletes a comment. For more information, see [Manage comments and replies](https://deve","category":"network","line_end":63,"severity":"low","line_start":63},{"id":"network:SKILL.md:64:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `get` — Gets a comment by ID. For more information, see [Manage comments and replies](https://deve","category":"network","line_end":64,"severity":"low","line_start":64},{"id":"network:SKILL.md:65:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `list` — Lists a file's comments. For more information, see [Manage comments and replies](https://","category":"network","line_end":65,"severity":"low","line_start":65},{"id":"network:SKILL.md:66:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `update` — Updates a comment with patch semantics. For more information, see [Manage comments and ","category":"network","line_end":66,"severity":"low","line_start":66},{"id":"network:SKILL.md:70:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `create` — Creates a shared drive. For more information, see [Manage shared drives](https://develo","category":"network","line_end":70,"severity":"low","line_start":70},{"id":"network:SKILL.md:71:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `get` — Gets a shared drive's metadata by ID. For more information, see [Manage shared drives](htt","category":"network","line_end":71,"severity":"low","line_start":71},{"id":"network:SKILL.md:72:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `hide` — Hides a shared drive from the default view. For more information, see [Manage shared driv","category":"network","line_end":72,"severity":"low","line_start":72},{"id":"network:SKILL.md:73:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `list` — Lists the user's shared drives. This method accepts the `q` parameter, which is a search ","category":"network","line_end":73,"severity":"low","line_start":73},{"id":"network:SKILL.md:74:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `unhide` — Restores a shared drive to the default view. For more information, see [Manage shared d","category":"network","line_end":74,"severity":"low","line_start":74},{"id":"network:SKILL.md:75:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `update` — Updates the metadata for a shared drive. For more information, see [Manage shared drive","category":"network","line_end":75,"severity":"low","line_start":75},{"id":"network:SKILL.md:79:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `copy` — Creates a copy of a file and applies any requested updates with patch semantics. For more","category":"network","line_end":79,"severity":"low","line_start":79},{"id":"network:SKILL.md:80:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `create` — Creates a file. For more information, see [Create and manage files](https://developers.","category":"network","line_end":80,"severity":"low","line_start":80},{"id":"network:SKILL.md:81:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `download` — Downloads the content of a file. For more information, see [Download and export files","category":"network","line_end":81,"severity":"low","line_start":81},{"id":"network:SKILL.md:82:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `export` — Exports a Google Workspace document to the requested MIME type and returns exported byt","category":"network","line_end":82,"severity":"low","line_start":82},{"id":"network:SKILL.md:83:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `generateIds` — Generates a set of file IDs which can be provided in create or copy requests. For ","category":"network","line_end":83,"severity":"low","line_start":83},{"id":"network:SKILL.md:84:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `get` — Gets a file's metadata or content by ID. For more information, see [Search for files and f","category":"network","line_end":84,"severity":"low","line_start":84},{"id":"network:SKILL.md:85:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `list` — Lists the user's files. For more information, see [Search for files and folders](https://","category":"network","line_end":85,"severity":"low","line_start":85},{"id":"network:SKILL.md:86:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `listLabels` — Lists the labels on a file. For more information, see [List labels on a file](https","category":"network","line_end":86,"severity":"low","line_start":86},{"id":"network:SKILL.md:87:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `modifyLabels` — Modifies the set of labels applied to a file. For more information, see [Set a la","category":"network","line_end":87,"severity":"low","line_start":87},{"id":"network:SKILL.md:89:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `watch` — Subscribes to changes to a file. For more information, see [Notifications for resource c","category":"network","line_end":89,"severity":"low","line_start":89},{"id":"network:SKILL.md:97:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `create` — Creates a permission for a file or shared drive. For more information, see [Share files","category":"network","line_end":97,"severity":"low","line_start":97},{"id":"network:SKILL.md:98:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `delete` — Deletes a permission. For more information, see [Share files, folders, and drives](http","category":"network","line_end":98,"severity":"low","line_start":98},{"id":"network:SKILL.md:99:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `get` — Gets a permission by ID. For more information, see [Share files, folders, and drives](http","category":"network","line_end":99,"severity":"low","line_start":99},{"id":"network:SKILL.md:100:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `list` — Lists a file's or shared drive's permissions. For more information, see [Share files, fol","category":"network","line_end":100,"severity":"low","line_start":100},{"id":"network:SKILL.md:101:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `update` — Updates a permission with patch semantics. For more information, see [Share files, fold","category":"network","line_end":101,"severity":"low","line_start":101},{"id":"network:SKILL.md:105:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `create` — Creates a reply to a comment. For more information, see [Manage comments and replies](h","category":"network","line_end":105,"severity":"low","line_start":105},{"id":"network:SKILL.md:106:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `delete` — Deletes a reply. For more information, see [Manage comments and replies](https://develo","category":"network","line_end":106,"severity":"low","line_start":106},{"id":"network:SKILL.md:107:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `get` — Gets a reply by ID. For more information, see [Manage comments and replies](https://develo","category":"network","line_end":107,"severity":"low","line_start":107},{"id":"network:SKILL.md:108:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `list` — Lists a comment's replies. For more information, see [Manage comments and replies](https:","category":"network","line_end":108,"severity":"low","line_start":108},{"id":"network:SKILL.md:109:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `update` — Updates a reply with patch semantics. For more information, see [Manage comments and re","category":"network","line_end":109,"severity":"low","line_start":109},{"id":"network:SKILL.md:113:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `delete` — Permanently deletes a file version. You can only delete revisions for files with binary","category":"network","line_end":113,"severity":"low","line_start":113},{"id":"network:SKILL.md:114:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `get` — Gets a revision's metadata or content by ID. For more information, see [Manage file revisi","category":"network","line_end":114,"severity":"low","line_start":114},{"id":"network:SKILL.md:115:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `list` — Lists a file's revisions. For more information, see [Manage file revisions](https://devel","category":"network","line_end":115,"severity":"low","line_start":115},{"id":"network:SKILL.md:116:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- `update` — Updates a revision with patch semantics. For more information, see [Manage file revisio","category":"network","line_end":116,"severity":"low","line_start":116},{"id":"filesystem:SKILL.md:16:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"> **PREREQUISITE:** Read `../gws-shared/SKILL.md` for auth, global flags, and security rules. If mis","category":"filesystem","line_end":16,"severity":"high","line_start":16},{"id":"filesystem:SKILL.md:26:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"| [`+upload`](../gws-drive-upload/SKILL.md) | Upload a file with automatic metadata |","category":"filesystem","line_end":26,"severity":"high","line_start":26},{"id":"blocker:SKILL.md:80:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- `create` — Creates a file. For more information, see [Create and manage files](https://developers.","category":"blocker","line_end":80,"severity":"low","line_start":80},{"id":"blocker:SKILL.md:81:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- `download` — Downloads the content of a file. For more information, see [Download and export files","category":"blocker","line_end":81,"severity":"low","line_start":81},{"id":"blocker:SKILL.md:88:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- `update` — Updates a file's metadata, content, or both. When calling this method, only populate fi","category":"blocker","line_end":88,"severity":"low","line_start":88}],"finding_verdicts":[{"id":"external_commands:SKILL.md:16:ruby-shell-backtick-execution","reason":"The backticks format a relative prerequisite path and a gws command in Markdown. No Ruby interpreter, shell substitution, or dynamic command execution appears here.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code-fence delimiters around a documented CLI example. They are not Ruby backtick execution or executable syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code-fence delimiters around a documented CLI example. They are not Ruby backtick execution or executable syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"The backticks format the +upload label inside a Markdown link to a sibling skill. The line does not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:54:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:83:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:93:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:105:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:106:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:113:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:123:ruby-shell-backtick-execution","reason":"The backticks format a Google Drive API method or parameter name in Markdown documentation. The line contains no Ruby or shell execution construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:129:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code-fence delimiters around a documented CLI example. They are not Ruby backtick execution or executable syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:135:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code-fence delimiters around a documented CLI example. They are not Ruby backtick execution or executable syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","reason":"The backticks format a command name and flag names in explanatory prose. No shell or Ruby execution construct is present.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:83:python-http-libraries","reason":"The text is the Drive API method name generateIds, not a Python HTTP import or request. This documentation-only line performs no network operation.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:32:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:36:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:37:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:38:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:47:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:48:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:52:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:53:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:54:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:58:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:62:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:63:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:64:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:65:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:66:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:70:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:71:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:72:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:73:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:74:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:75:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:79:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:80:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:81:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:82:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:83:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:84:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:85:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:86:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:87:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:89:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:97:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:98:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:99:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:100:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:101:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:105:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:106:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:107:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:108:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:109:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:113:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:114:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:115:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:116:hardcoded-url","reason":"The URL is a Markdown link to official developers.google.com documentation. It is not a request target used by executable code and transmits no data.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:16:path-traversal-sequence","reason":"The ../ sequence is a fixed Markdown reference to a sibling prerequisite skill. It is not derived from input and is not used in a filesystem operation.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:26:path-traversal-sequence","reason":"The ../ sequence is a fixed relative Markdown link to the upload helper skill. It does not access a user-controlled path or perform traversal.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:80:system-reconnaissance","reason":"This line documents a Google Drive file API method and its behavior. It does not enumerate the host system, processes, users, or environment.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:81:system-reconnaissance","reason":"This line documents a Google Drive file API method and its behavior. It does not enumerate the host system, processes, users, or environment.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:88:system-reconnaissance","reason":"This line documents a Google Drive file API method and its behavior. It does not enumerate the host system, processes, users, or environment.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[{"title":"Consequential Drive Operations Need Confirmation","severity":"medium","locations":[{"file":"SKILL.md","line_end":16,"line_start":16},{"file":"SKILL.md","line_end":38,"line_start":38},{"file":"SKILL.md","line_end":63,"line_start":63},{"file":"SKILL.md","line_end":88,"line_start":88},{"file":"SKILL.md","line_end":98,"line_start":98},{"file":"SKILL.md","line_end":101,"line_start":101},{"file":"SKILL.md","line_end":113,"line_start":113}],"confidence":0.95,"description":"The skill lists approval, deletion, file update, permission change, and revision deletion methods without local confirmation requirements. Broad requests could cause data loss or access changes.","confidence_reasoning":"The methods are explicitly documented at the cited lines. Confidence is slightly reduced because line 16 delegates security rules to a sibling skill."}],"subject_marketplace_commit_sha":"286d37c9c189ddd1aafd3548415fb031d1df79d5","subject_content_hash":"ab6e66702196c465e1e58a7a9735b31687625079d4fbfa47d1835db26d9b1696","subject_tree_hash":"71ebeb163f29ccb8fc4f96e322e7d5432f7340056c161352caf3c635f41ca072","subject_plugin_path":"skills/googleworkspace/gws-drive","audit_payload_hash":"77c99ee72ed88fd570c464699172dbb1","confirmed_risk_level":"medium","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"286d37c9c189ddd1aafd3548415fb031d1df79d5","contentHash":"ab6e66702196c465e1e58a7a9735b31687625079d4fbfa47d1835db26d9b1696","treeHash":"71ebeb163f29ccb8fc4f96e322e7d5432f7340056c161352caf3c635f41ca072","pluginPath":"skills/googleworkspace/gws-drive","auditPayloadHash":"77c99ee72ed88fd570c464699172dbb1"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/googleworkspace-gws-drive/audits/5/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}