calendar-prep

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security threats or malicious patterns were identified in the skill's instructions, metadata, or scripts.
  • [COMMAND_EXECUTION]: The skill utilizes a local script scripts/meeting_prep_briefer.py to format briefing documents. Technical review confirms the script is limited to parsing JSON and printing text to the console using standard Python libraries, with no network access or dangerous system-level operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill contains an attack surface for indirect prompt injection as it processes external data from assets/meeting_input.json.
  • Ingestion points: The file assets/meeting_input.json is read by the meeting_prep_briefer.py script.
  • Boundary markers: None identified in the skill instructions to delimit untrusted content.
  • Capability inventory: The skill is limited to local text formatting and stdout printing; no file-writing, network, or high-privilege capabilities are present.
  • Sanitization: The input is parsed as JSON, but the resulting strings are not sanitized before being formatted into the markdown briefing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 07:29 AM
Security Audit — agent-trust-hub — calendar-prep