google-appsheet-production

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The scripts/appsheet_docs.py utility allows the agent to fetch official technical documentation from support.google.com/appsheet. The script includes hardcoded domain validation to ensure network requests are restricted to this well-known service and prevents redirects to external domains.
  • [CREDENTIALS_UNSAFE]: The scripts/validate_delivery.py tool includes a proactive security scanner that uses regular expressions to detect and flag potential hardcoded credentials, API keys, or private keys within the generated project files. This facilitates the skill's non-negotiable rule against handling sensitive secrets.
  • [PROMPT_INJECTION]: The instructions in SKILL.md establish robust operational boundaries through 'Non-Negotiable Rules'. These rules explicitly instruct the agent to avoid false completions, refuse to handle user credentials, and treat UI-level display logic as distinct from technical row-level security filters.
  • [COMMAND_EXECUTION]: The skill uses local Python scripts (scripts/scaffold_delivery.py, scripts/validate_delivery.py) to manage the file structure of the AppSheet delivery pack. These scripts use standard Python libraries to perform benign file operations and scaffolding tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 12:28 PM
Security Audit — agent-trust-hub — google-appsheet-production