prep
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill synthesizes data from external and local sources (e.g., meeting notes, CRM data), which provides a surface for potential indirect prompt injection if these sources contain malicious instructions.\n
- Ingestion points: Reads data from
context/,wiki/,decisions/log.md,connections.md, and external MCP services (Calendar, CRM, Notes).\n - Boundary markers: The skill includes a 'Verification Gate' instructing the agent to cite every fact and flag unconfirmed information, reducing the likelihood of obeying embedded instructions.\n
- Capability inventory: The skill uses
/graph-queryand executes a local helper scripttools/open_loops.py.\n - Sanitization: Relies on explicit citation and verification instructions to manage data integrity instead of automated filtering.\n- [COMMAND_EXECUTION]: The skill invokes a local utility script
tools/open_loops.pyto collect task data. This execution is confined to the local environment and does not involve remote code downloads or execution.
Audit Metadata