google-trends-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the vendor-provided postplus command-line interface to execute search-intent research tasks, perform diagnostic checks (postplus doctor), and manage software updates. These operations are consistent with the skill's stated purpose of conducting marketplace research.
  • [DATA_EXPOSURE]: Research data and watchlist caches are managed within a dedicated local directory (.postplus/google-trends/), which follows best practices for local storage and allows for user oversight of processed information.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a data ingestion surface as it processes external search trend results.
  • Ingestion points: External data is collected into ./result.json via the google-trends-fast command.
  • Boundary markers: The instructions explicitly require the agent to "separate observation from inference" and validate records against a specific schema defined in the vendor's shared reference files.
  • Capability inventory: The agent is restricted to postplus CLI subcommands and does not have arbitrary code execution capabilities.
  • Sanitization: The workflow involves filtering for specific "trend signals" and normalized outputs, reducing the risk of processing malicious metadata embedded in search trends.
  • [SAFE]: The authentication flow (postplus auth login) is designed to be user-interactive, requiring the agent to provide a URL for the user to visit rather than attempting to handle credentials or tokens automatically.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 03:07 PM
Security Audit — agent-trust-hub — google-trends-research