using-glean
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: Functional Verification. The skill is a collection of Markdown documentation and instructions for using the Glean MCP server. It does not contain any executable scripts, remote code downloads, or obfuscated content.
- [SAFE]: Data Access Management. While the skill facilitates access to sensitive enterprise data (emails, documents, calendars), it does so via the Glean MCP tools which are subject to the user's organizational permissions and security policies.
- [SAFE]: Indirect Prompt Injection Surface. The skill is designed to process untrusted data from sources such as emails and meeting transcripts. Ingestion points: search, gmail_search, outlook_search, read_document, and meeting_lookup tools. Boundary markers: The reference/synthesis.md and reference/vetting.md files provide guidance on how to structure output and verify data, though they do not define technical delimiters for the ingested content. Capability inventory: The skill's tools are limited to information retrieval and synthesis; no arbitrary code execution, file system modification, or non-whitelisted network capabilities are present. Sanitization: The reference/vetting.md file establishes a manual vetting protocol for the agent to assess source relevance, freshness, and authority.
Audit Metadata