glean-entities
Pass
Audited by Gen Agent Trust Hub on Mar 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes the
gleanCLI to list and read people profiles and entities. - [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it reads data from the Glean database into the prompt.
- Ingestion points: Results from
glean entities listandglean entities read-peoplein SKILL.md. - Boundary markers: No boundary markers or delimiters are used for the external data.
- Capability inventory: Shell command execution via the
gleantool. - Sanitization: No sanitization of ingested data is performed.
Audit Metadata