Back to skill

Security audit

Multi-API Data Pipeline to Google Sheets

Security checks across malware telemetry and agentic risk

Overview

This skill clearly describes a user-configured pipeline that sends selected API data to Google Sheets, with sensitive access that is expected for that purpose.

Before installing, confirm that the target Google Sheet sharing settings, service-account permissions, connected API scopes, and scheduled sync frequency match your data policy. Avoid regulated or highly sensitive data unless you are comfortable with storage in Google Sheets and with temporary local buffering during failed writes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly moves data from multiple APIs into Google Sheets but does not warn users that their data will be transmitted to third-party services and persisted in an external cloud document. This can lead users to unknowingly expose sensitive business, customer, or internal API data to Google Sheets sharing, retention, and access-control risks.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.