ffe-schedule

Pass

Audited by Gen Agent Trust Hub on Apr 3, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted input from external files and user notes, which presents an indirect prompt injection surface.
  • Ingestion points: Raw notes, CSV content, and file paths are accepted as input in SKILL.md.
  • Boundary markers: There are no explicit instructions for the agent to treat external data with delimiters or safety warnings.
  • Capability inventory: The skill has access to Write, Edit, Bash, and Google Sheets update tools (mcp__google__sheets_values_update) as defined in the frontmatter of SKILL.md.
  • Sanitization: The skill does not describe any validation or sanitization of the input data before processing.
  • [EXTERNAL_DOWNLOADS]: The README.md file includes instructions to download the skill repository from its source on GitHub.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 3, 2026, 12:42 PM
Security Audit — agent-trust-hub — ffe-schedule