meeting-follow-up

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted meeting notes and transcripts, which creates a surface for indirect prompt injection attacks where an attacker could embed malicious instructions in a meeting transcript to manipulate the resulting follow-up draft.
  • Ingestion points: The skill retrieves external meeting content through instructions in SKILL.md to "Find the requested meeting" and "Retrieve the selected note" including its transcript.
  • Boundary markers: The instructions do not define clear delimiters or provide the agent with instructions to ignore potential commands embedded within the meeting text.
  • Capability inventory: The skill's capabilities are limited to drafting text; it explicitly states it cannot send messages or modify notes, which significantly limits the impact of a successful injection.
  • Sanitization: There are no procedures defined to sanitize or validate the content of the meeting notes before the agent processes them.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 09:09 AM
Security Audit — agent-trust-hub — meeting-follow-up