analytics-report
Warn
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill accesses local configuration files including
config.yamland project-specific.yamland.mcp.jsonfiles. These files likely contain sensitive information such as database connection strings, API tokens, and project metadata. - [COMMAND_EXECUTION]: Utilizes the
Bashtool to executepsqlfor database queries and shell commands for file system operations (ls,sort,head). - [COMMAND_EXECUTION]: Recommends the use of the
--dangerously-skip-permissionsflag for headless automation. This flag explicitly bypasses the agent's built-in security prompts for tool execution, increasing the risk of unauthorized actions if the agent's context is manipulated. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it processes external, potentially attacker-controlled data.
- Ingestion points: Data is ingested from Google Search Console (top queries) and Google Analytics via MCP tools in
SKILL.md(Step 3: Collect Data). - Boundary markers: Absent. The instructions do not specify any delimiters or safety markers when interpolating external data into the report templates.
- Capability inventory: The agent has access to
Bash(for database and file operations),Write(to save reports), andRead(to access configurations and templates) as described inSKILL.md. - Sanitization: Absent. There are no instructions provided for sanitizing or escaping the data retrieved from external APIs or databases before processing.
Audit Metadata