calendar-automation
Pass
Audited by Gen Agent Trust Hub on Jul 8, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill incorporates untrusted data from external sources into its automated workflows, which could be used for indirect prompt injection attacks.
- Ingestion points: Workflow steps in
SKILL.mdextract data from meeting titles, descriptions, attendee profiles, and user-provided answers in booking forms (Calendly). - Boundary markers: The provided templates do not utilize delimiters or specific instructions to the agent to disregard malicious commands embedded within the fetched calendar or CRM data.
- Capability inventory: The skill utilizes tools for updating calendar events, sending Slack messages, and writing to Google Sheets, providing a mechanism for an injection to influence office communication or data records.
- Sanitization: There is no evidence of input validation or content filtering for the data retrieved from external integrations (HubSpot, LinkedIn, Calendly).
Audit Metadata