skills/cursor/plugins/google-sheets/Gen Agent Trust Hub

google-sheets

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates reading data from external Google Sheets, which serves as an ingestion point for untrusted content.
  • Ingestion points: The tools read_range and get_spreadsheet (documented in SKILL.md) are used to retrieve values and structural metadata from remote spreadsheets.
  • Boundary markers: The provided instructions do not specify any delimiters or safety boundaries to separate spreadsheet data from the agent's internal logic.
  • Capability inventory: The skill allows the agent to modify spreadsheet values, change structural layouts, and perform file management tasks via referenced Google Drive tools.
  • Sanitization: There are no documented steps for validating or sanitizing the data fetched from sheets before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 09:41 PM
Security Audit — agent-trust-hub — google-sheets