google-search-console

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to use a command-line tool named treg to list and manage API connections and resources (e.g., treg connections ls and treg connections resources <id>). These are standard operational commands.
  • [COMMAND_EXECUTION]: The skill mentions the existence of write capabilities (PUT/DELETE for sitemaps) but explicitly instructs the agent to obtain human approval before execution, which is a security best practice.
  • [EXTERNAL_DOWNLOADS]: The skill includes reference links to official Google developer documentation and support pages for the Search Analytics and URL Inspection APIs. These are trusted, well-known sources.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes an ingestion surface for external data from Google Search Console and Google Analytics 4. While it does not include specific sanitization logic, it provides detailed interpretation rules to help the agent distinguish between artifacts and real trends, reducing the risk of being misled by malformed or incomplete API responses.
  • Ingestion points: API outputs from Google Search Console and GA4 retrieved via treg or direct API calls.
  • Boundary markers: The skill provides contextual rules (e.g., "End ranges ≥3 days before today") to define valid data boundaries.
  • Capability inventory: Reading search analytics, sitemaps, and URL inspection status; restricted write access to sitemaps.
  • Sanitization: The skill relies on cross-referencing multiple data sources (GSC and GA4) to validate findings.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 10:50 PM
Security Audit — agent-trust-hub — google-search-console