tencent-docs
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The
OperationSheettool insheet/api/operation-api.mdallows for the generation and execution of JavaScript-based scripts for complex spreadsheet manipulations. This is a core feature for advanced table editing and is managed through structured AI-generated commands.\n- [PROMPT_INJECTION]: The skill includes explicit defensive instructions insheet/api/js-script-rule.mdto prevent the AI model from responding to injection attempts or disclosing internal configurations. This acts as a security guardrail rather than a threat.\n- [EXTERNAL_DOWNLOADS]: Thesetup.shscript automates the installation of themcportertool via the global NPM registry. This is a legitimate administrative procedure required for the skill to communicate with the MCP host.\n- [INDIRECT_PROMPT_INJECTION]: Thescrape_urlandget_contentfeatures provide mechanisms for the agent to ingest external content from the web or other documents. This represents a standard document processing attack surface that is mitigated by the safety principles defined in the skill.
Audit Metadata