gsc-ai-performance

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill performs legitimate marketing data analysis and does not contain malicious code, hidden URLs, or persistence mechanisms.
  • [COMMAND_EXECUTION]: The skill invokes a local script gsc-ai-performance.py via python. This execution is scoped to the plugin directory and is used solely for data transformation.
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface through its ingestion of external CSV data. 1. Ingestion points: CSV files located in ${CLAUDE_PLUGIN_DATA}/{brand}/seo/gsc-ai-performance/{date}/. 2. Boundary markers: None defined in the skill markdown. 3. Capability inventory: Execution of a Python script and reading of local brand configuration files. 4. Sanitization: Not specified in the instructions; logic resides within the external script.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 06:03 PM
Security Audit — agent-trust-hub — gsc-ai-performance