opencode-sheets-gas
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: A comprehensive review of the code snippets and instructions confirms that there are no malicious patterns, obfuscation, or security vulnerabilities present.
- [PROMPT_INJECTION]: The skill contains instructional rules for the agent to guide users safely (e.g., warning against collecting personally identifiable information). These are benign UX enhancements and safety guardrails, not attempts to bypass underlying model safety filters.
- [COMMAND_EXECUTION]: No shell commands, privilege escalation, or dangerous execution patterns were found. The skill operates entirely within the cloud-based Google Apps Script environment.
- [DATA_EXFILTRATION]: Data operations are restricted to writing to and reading from the user's Google Sheets. The skill explicitly advises users on data privacy and warns against hardcoding sensitive identifiers in public environments.
Audit Metadata