meeting-prep
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were detected. The skill is instructional and its behavior aligns with the primary purpose of providing meeting research and sales intelligence.\n- [NO_CODE]: The skill consists entirely of markdown-based instructions and metadata. It does not include any executable scripts, binaries, or dependencies that could pose a direct execution risk.\n- [DATA_EXFILTRATION]: The skill manages professional contact information (emails, phone numbers). This is a core feature of the tool and is performed via the vendor's (Explorium) infrastructure. The instructions limit phone number retrieval to scenarios where the user explicitly intends to perform outreach.\n- [PROMPT_INJECTION]: An indirect prompt injection surface is present because the skill processes untrusted external data.\n
- Ingestion points: LinkedIn posts, website changes, and business events (Step 3 and 4).\n
- Boundary markers: Absent; the instructions do not specify delimiters to separate external content from the agent's instructions.\n
- Capability inventory: The skill is limited to information synthesis; it possesses no file system write access, arbitrary command execution, or uncontrolled network capabilities.\n
- Sanitization: The skill mitigates risks by instructing the agent to tag claims by source category and to flag stale data for verification.
Audit Metadata