@tank/google-sheets

Pass

Audited by Gen Agent Trust Hub on May 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill communicates with well-known Google services to perform spreadsheet operations and handle authentication. Details: Network access is restricted to official domains including *.googleapis.com, accounts.google.com, and oauth2.googleapis.com as defined in tank.json.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external spreadsheets, which is an inherent part of its functionality but creates a surface for indirect instructions. Details: \n
  • Ingestion points: Data read from cells, ranges, and sheets via the Google Sheets API (SKILL.md).\n
  • Boundary markers: None specified in the instructions to separate data from agent instructions.\n
  • Capability inventory: Filesystem read access to the local directory (./**) and network operations to Google APIs (tank.json).\n
  • Sanitization: No explicit validation or sanitization of spreadsheet content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
May 31, 2026, 11:04 PM
Security Audit — agent-trust-hub — @tank/google-sheets