risk-desk

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The script risk-desk.ts executes the gws (Google Workspace CLI) command to read and write data to a Google Sheet. This execution is limited to specific spreadsheet interactions and occurs only when the --arm flag is manually provided.
  • [EXTERNAL_DOWNLOADS]: The skill fetches real-time market data from query1.finance.yahoo.com. This is a well-known service and the data retrieved (stock prices, moving averages) is used strictly for risk evaluation as described in the documentation.
  • [DATA_EXFILTRATION]: While the skill reads sensitive financial position data from local CSV files and sends it to a remote Google Sheet, the destination is a well-known service (Google Sheets) and the behavior is the primary intended function of the skill. No exfiltration to untrusted or unknown domains was observed.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 02:21 PM
Security Audit — agent-trust-hub — risk-desk