meeting-prep
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data, including inbound lead information and potentially data from connected CRM or call recording systems. \n
- Ingestion points: Lead data in Mode 1 and context from CRM, email, or recorders in Step 0. \n
- Boundary markers: The instructions lack specific delimiters or warnings to ignore potential instructions embedded within the ingested data. \n
- Capability inventory: The agent has access to an 'execute' tool for running JavaScript logic and fetching external content via tools like 'web_search_live'. \n
- Sanitization: No sanitization or validation mechanisms are specified for handling the ingested external data. \n- [DYNAMIC_EXECUTION]: The skill employs a vendor-provided 'execute' tool to perform JavaScript-based data processing at runtime. The instructions guide the agent in generating scripts based on static templates for data identification and enrichment. \n- [EXTERNAL_DOWNLOADS]: The skill references the Crustdata MCP server and official GitHub releases for its configuration. These are recognized as legitimate resources provided by the skill author.
Audit Metadata