meeting-follow-up
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted meeting notes and transcripts, which creates a surface for indirect prompt injection attacks where an attacker could embed malicious instructions in a meeting transcript to manipulate the resulting follow-up draft.
- Ingestion points: The skill retrieves external meeting content through instructions in
SKILL.mdto "Find the requested meeting" and "Retrieve the selected note" including its transcript. - Boundary markers: The instructions do not define clear delimiters or provide the agent with instructions to ignore potential commands embedded within the meeting text.
- Capability inventory: The skill's capabilities are limited to drafting text; it explicitly states it cannot send messages or modify notes, which significantly limits the impact of a successful injection.
- Sanitization: There are no procedures defined to sanitize or validate the content of the meeting notes before the agent processes them.
Audit Metadata