calendar-automation

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill incorporates untrusted data from external sources into its automated workflows, which could be used for indirect prompt injection attacks.
  • Ingestion points: Workflow steps in SKILL.md extract data from meeting titles, descriptions, attendee profiles, and user-provided answers in booking forms (Calendly).
  • Boundary markers: The provided templates do not utilize delimiters or specific instructions to the agent to disregard malicious commands embedded within the fetched calendar or CRM data.
  • Capability inventory: The skill utilizes tools for updating calendar events, sending Slack messages, and writing to Google Sheets, providing a mechanism for an injection to influence office communication or data records.
  • Sanitization: There is no evidence of input validation or content filtering for the data retrieved from external integrations (HubSpot, LinkedIn, Calendly).
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 07:45 PM
Security Audit — agent-trust-hub — calendar-automation