google-trends-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the vendor-provided
postpluscommand-line interface to execute search-intent research tasks, perform diagnostic checks (postplus doctor), and manage software updates. These operations are consistent with the skill's stated purpose of conducting marketplace research. - [DATA_EXPOSURE]: Research data and watchlist caches are managed within a dedicated local directory (
.postplus/google-trends/), which follows best practices for local storage and allows for user oversight of processed information. - [INDIRECT_PROMPT_INJECTION]: The skill has a data ingestion surface as it processes external search trend results.
- Ingestion points: External data is collected into
./result.jsonvia thegoogle-trends-fastcommand. - Boundary markers: The instructions explicitly require the agent to "separate observation from inference" and validate records against a specific schema defined in the vendor's shared reference files.
- Capability inventory: The agent is restricted to
postplusCLI subcommands and does not have arbitrary code execution capabilities. - Sanitization: The workflow involves filtering for specific "trend signals" and normalized outputs, reducing the risk of processing malicious metadata embedded in search trends.
- [SAFE]: The authentication flow (
postplus auth login) is designed to be user-interactive, requiring the agent to provide a URL for the user to visit rather than attempting to handle credentials or tokens automatically.
Audit Metadata