meeting-prep
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from an external source (Monologue notes and transcripts), which creates a surface for indirect prompt injection attacks.
- Ingestion points: The instructions direct the agent to search for and retrieve "Monologue notes" and "transcripts" (SKILL.md).
- Boundary markers: There are no explicit instructions or delimiters defined to separate the retrieved note content from the agent's instructions or to warn the agent against following instructions found within the notes.
- Capability inventory: The skill requires the agent to use search and retrieval tools to fetch data from an external system.
- Sanitization: The instructions do not include any logic for sanitizing or validating the content of the retrieved notes before they are processed into a briefing.
Audit Metadata