ffe-schedule
Pass
Audited by Gen Agent Trust Hub on Apr 3, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted input from external files and user notes, which presents an indirect prompt injection surface.
- Ingestion points: Raw notes, CSV content, and file paths are accepted as input in SKILL.md.
- Boundary markers: There are no explicit instructions for the agent to treat external data with delimiters or safety warnings.
- Capability inventory: The skill has access to Write, Edit, Bash, and Google Sheets update tools (mcp__google__sheets_values_update) as defined in the frontmatter of SKILL.md.
- Sanitization: The skill does not describe any validation or sanitization of the input data before processing.
- [EXTERNAL_DOWNLOADS]: The README.md file includes instructions to download the skill repository from its source on GitHub.
Audit Metadata