gtm-meeting-prep

Pass

Audited by Gen Agent Trust Hub on Jun 27, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests and processes untrusted data from external web sources.
  • Ingestion points: External intelligence gathered via the WebSearch tool and subagent tasks in Step 2 regarding companies, persons, and industries.
  • Boundary markers: The instructions do not specify any delimiters or safety markers to differentiate between trusted instructions and potentially malicious content retrieved from the web.
  • Capability inventory: The skill utilizes Read, Write, and Task capabilities, which could be leveraged if an attacker successfully injects instructions via a researched website or profile.
  • Sanitization: There is no evidence of content sanitization, filtering, or validation for the data retrieved from external sources before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 27, 2026, 12:52 PM
Security Audit — agent-trust-hub — gtm-meeting-prep