google-appsheet-production
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
scripts/appsheet_docs.pyutility allows the agent to fetch official technical documentation fromsupport.google.com/appsheet. The script includes hardcoded domain validation to ensure network requests are restricted to this well-known service and prevents redirects to external domains. - [CREDENTIALS_UNSAFE]: The
scripts/validate_delivery.pytool includes a proactive security scanner that uses regular expressions to detect and flag potential hardcoded credentials, API keys, or private keys within the generated project files. This facilitates the skill's non-negotiable rule against handling sensitive secrets. - [PROMPT_INJECTION]: The instructions in
SKILL.mdestablish robust operational boundaries through 'Non-Negotiable Rules'. These rules explicitly instruct the agent to avoid false completions, refuse to handle user credentials, and treat UI-level display logic as distinct from technical row-level security filters. - [COMMAND_EXECUTION]: The skill uses local Python scripts (
scripts/scaffold_delivery.py,scripts/validate_delivery.py) to manage the file structure of the AppSheet delivery pack. These scripts use standard Python libraries to perform benign file operations and scaffolding tasks.
Audit Metadata