airtable-automation
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from Airtable (records and comments) which are untrusted external sources.
- Ingestion points: SKILL.md describes tools like
AIRTABLE_LIST_RECORDS,AIRTABLE_GET_RECORD, andAIRTABLE_LIST_COMMENTSthat fetch external data. - Boundary markers: The instructions do not define specific delimiters or "ignore" instructions for the fetched data.
- Capability inventory: The skill utilizes tools for modifying Airtable data (
AIRTABLE_CREATE_RECORD,AIRTABLE_UPDATE_RECORD,AIRTABLE_DELETE_RECORD). - Sanitization: No sanitization or validation of the fetched record content is mentioned.
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to add an external MCP server URL to their configuration.
- Evidence: Mentions adding
https://rube.app/mcpas an MCP server in the client configuration.
Audit Metadata