retain
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external content, specifically call transcripts and client feedback, creating a surface for potential instruction injection.
- Ingestion points: Meeting transcripts from Fathom (referenced in
references/qbr.md) and client communications from WhatsApp or Gmail (referenced inreferences/check-in.md). - Boundary markers: There are no documented boundary markers or "ignore previous instructions" warnings applied when the agent processes external transcript data.
- Capability inventory: The agent possesses powerful capabilities including
bash,run_command, and file manipulation tools (write_to_file,replace_file_content) as defined inagents/openai.yaml. - Sanitization: The skill lacks explicit sanitization or validation logic for external content before it is used to summarize priorities or log business decisions.
Audit Metadata