catch-up

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for Indirect Prompt Injection as it ingests untrusted data from external sources during Phase 2 (including meeting notes, direct mentions, and announcements via meeting_lookup and search tools). There are no explicit boundary markers or delimiters defined to isolate untrusted content, and no sanitization or filtering logic is provided to prevent the agent from obeying instructions embedded in the retrieved data. However, the capability inventory is limited to information retrieval and formatting within the Glean ecosystem, with no evidence of high-risk capabilities like shell execution, file system writes, or unauthorized network operations.
  • [SAFE]: No suspicious patterns were detected regarding credential handling, obfuscation, or persistence mechanisms. The tool usage and documentation references (e.g., using-glean/reference/) are consistent with the vendor author 'gleanwork'.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 06:51 PM
Security Audit — agent-trust-hub — catch-up