recipe-create-events-from-sheet

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to read data from a Google Sheet and use it to populate Google Calendar events, which creates a surface where malicious instructions hidden in the spreadsheet could be processed by the agent.
  • Ingestion points: External data is ingested from a spreadsheet via the gws sheets +read command as described in Step 1 (SKILL.md).
  • Boundary markers: The instructions do not define boundary markers or provide the agent with guidance to ignore potential instructions embedded within the spreadsheet data.
  • Capability inventory: The skill possesses the capability to modify the user's Google Calendar via the gws calendar +insert command (SKILL.md).
  • Sanitization: There are no explicit steps provided to sanitize, validate, or escape the content retrieved from the spreadsheet before it is passed to the calendar insertion tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:12 AM
Security Audit — agent-trust-hub — recipe-create-events-from-sheet