googlesheets-automation
Pass
Audited by Gen Agent Trust Hub on Feb 20, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [Prompt Injection] (LOW): The skill implements an indirect prompt injection surface by reading external data into the agent context. * Ingestion points: Data retrieved from spreadsheets using tools like GOOGLESHEETS_BATCH_GET and GOOGLESHEETS_VALUES_GET. * Boundary markers: No specific boundary markers or instruction-ignoring delimiters are defined for the spreadsheet content. * Capability inventory: The skill possesses extensive write and delete capabilities, including GOOGLESHEETS_BATCH_UPDATE, GOOGLESHEETS_UPSERT_ROWS, and GOOGLESHEETS_DELETE_DIMENSION. * Sanitization: No data validation or sanitization logic is specified for the ingested content.
- [External Downloads] (LOW): The skill instructs users to connect to a remote MCP endpoint (https://rube.app/mcp). While this is the intended transport mechanism for the Composio toolkit, it introduces a third-party dependency for all data processing operations.
Audit Metadata