airtable-automation

Pass

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from Airtable (records and comments) which are untrusted external sources.
  • Ingestion points: SKILL.md describes tools like AIRTABLE_LIST_RECORDS, AIRTABLE_GET_RECORD, and AIRTABLE_LIST_COMMENTS that fetch external data.
  • Boundary markers: The instructions do not define specific delimiters or "ignore" instructions for the fetched data.
  • Capability inventory: The skill utilizes tools for modifying Airtable data (AIRTABLE_CREATE_RECORD, AIRTABLE_UPDATE_RECORD, AIRTABLE_DELETE_RECORD).
  • Sanitization: No sanitization or validation of the fetched record content is mentioned.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to add an external MCP server URL to their configuration.
  • Evidence: Mentions adding https://rube.app/mcp as an MCP server in the client configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 8, 2026, 09:46 PM