product-spec-bulk-cleanup

Pass

Audited by Gen Agent Trust Hub on Apr 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security vulnerabilities were detected in the skill's instructions or workflow. The code is well-structured and focuses on data normalization.
  • [DATA_EXFILTRATION]: The skill integrates with Google Sheets using official MCP tools (mcp__google__sheets_values_get, mcp__google__sheets_values_update) to manage data. This usage is transparent and aligns with the skill's stated purpose of cleaning shared product libraries and master sheets.
  • [PROMPT_INJECTION]: While the skill processes external data (CSV files, Google Sheets, and pasted tables), the risk of indirect prompt injection is mitigated by the highly specific and structured normalization rules. The agent is instructed to perform constrained text transformations (e.g., casing, splitting dimensions, and category mapping) rather than open-ended analysis of the input data.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 3, 2026, 12:42 PM
Security Audit — agent-trust-hub — product-spec-bulk-cleanup