analytics-report

Warn

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill accesses local configuration files including config.yaml and project-specific .yaml and .mcp.json files. These files likely contain sensitive information such as database connection strings, API tokens, and project metadata.
  • [COMMAND_EXECUTION]: Utilizes the Bash tool to execute psql for database queries and shell commands for file system operations (ls, sort, head).
  • [COMMAND_EXECUTION]: Recommends the use of the --dangerously-skip-permissions flag for headless automation. This flag explicitly bypasses the agent's built-in security prompts for tool execution, increasing the risk of unauthorized actions if the agent's context is manipulated.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it processes external, potentially attacker-controlled data.
  • Ingestion points: Data is ingested from Google Search Console (top queries) and Google Analytics via MCP tools in SKILL.md (Step 3: Collect Data).
  • Boundary markers: Absent. The instructions do not specify any delimiters or safety markers when interpolating external data into the report templates.
  • Capability inventory: The agent has access to Bash (for database and file operations), Write (to save reports), and Read (to access configurations and templates) as described in SKILL.md.
  • Sanitization: Absent. There are no instructions provided for sanitizing or escaping the data retrieved from external APIs or databases before processing.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 16, 2026, 11:34 AM