google-classroom-automation
Pass
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill directs the agent to connect to an external MCP server at
https://rube.app/mcp. This is a vendor-provided service from ComposioHQ and is a standard requirement for the skill's operation.\n- [COMMAND_EXECUTION]: Automation is performed via tools such asRUBE_MULTI_EXECUTE_TOOLandRUBE_REMOTE_WORKBENCH. These tools are executed within the vendor's MCP environment to manage Google Classroom tasks.\n- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection from classroom content which is used as input for tool operations.\n - Ingestion points: External data from Google Classroom retrieved via MCP tools (e.g., assignment instructions, classroom posts).\n
- Boundary markers: No delimiters or safety instructions regarding the isolation of untrusted data were identified in the skill documentation.\n
- Capability inventory: Execution of arbitrary Google Classroom tools via
RUBE_MULTI_EXECUTE_TOOLandRUBE_REMOTE_WORKBENCH.\n - Sanitization: There are no instructions provided to sanitize, escape, or validate the content retrieved from external sources before it is processed by the agent.
Audit Metadata