market-research-digest

Pass

Audited by Gen Agent Trust Hub on Apr 2, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8) because it ingests untrusted data from multiple external sources. 1. Ingestion points: Files and links within the Google Drive research folder (INPUT_FOLDER) and Granola meeting notes from the last 30 days. 2. Boundary markers: The prompt template lacks delimiters or instructions to ignore embedded instructions in the source files. 3. Capability inventory: The skill can read private files, access meeting transcripts, search the web, and write files to Google Drive. 4. Sanitization: No evidence of sanitization or content validation for retrieved data.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 2, 2026, 08:18 PM
Security Audit — agent-trust-hub — market-research-digest