skills/aahl/skills/trendspyg/Gen Agent Trust Hub

trendspyg

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the execution of the trendspyg Python package using uvx. This is the primary functionality defined by the skill.
  • [EXTERNAL_DOWNLOADS]: The skill uses npx to run mcporter, which is a well-known utility used to bridge CLI tools with the Model Context Protocol (MCP).
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external Google Trends sources. 1. Ingestion points: Data enters the agent context through the trendspyg-call tool which retrieves trending topics and keyword analysis. 2. Boundary markers: None are specified in the instructions to distinguish external trend data from system prompts. 3. Capability inventory: The skill utilizes shell aliases for tool execution (uvx, npx) and data processing (jq). 4. Sanitization: No explicit sanitization or filtering of the retrieved trend data is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 10:09 AM
Security Audit — agent-trust-hub — trendspyg