meeting-prep
Pass
Audited by Gen Agent Trust Hub on May 4, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its core function of processing untrusted data from external sources.
- Ingestion points: The agent retrieves data from Google Calendar event descriptions (SKILL.md, Step 1) and the bodies of recent Gmail threads (SKILL.md, Step 2).
- Boundary markers: The instructions do not provide delimiters or specific directives for the agent to ignore instructions that might be embedded within the retrieved calendar or email content.
- Capability inventory: The agent has the capability to read sensitive personal data (emails/calendar) and perform web searches based on that data.
- Sanitization: No sanitization, filtering, or validation logic is defined to handle potentially malicious content within the external data sources before they are summarized for the user.
Audit Metadata