google-sheets

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads and executes the @useclawlink/cli package from the NPM registry to provide its core functionality.
  • [COMMAND_EXECUTION]: The skill instructs the agent to run various shell commands using npx @useclawlink/cli to manage spreadsheet data and authenticate with the service.
  • [PROMPT_INJECTION]: The skill creates an indirect prompt injection surface by ingesting untrusted data from external Google Sheets. (1) Ingestion points: googlesheets_values_get, googlesheets_batch_get, and googlesheets_lookup_spreadsheet_row in SKILL.md. (2) Boundary markers: None present. (3) Capability inventory: Shell command execution and action execution via npx @useclawlink/cli in SKILL.md. (4) Sanitization: No sanitization or validation of spreadsheet content is performed before the agent processes it.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 02:43 PM
Security Audit — agent-trust-hub — google-sheets