granola
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted meeting transcripts which could contain adversarial instructions designed to influence agent behavior.\n
- Ingestion points: Meeting transcripts retrieved via the
granola meeting --transcriptcommand.\n - Boundary markers: No delimiters or safety instructions are provided to distinguish meeting content from agent commands.\n
- Capability inventory: Local shell execution via the
granolaCLI and network capability viacurlto a local service endpoint.\n - Sanitization: There is no mention of content filtering or validation for retrieved transcripts.\n- [COMMAND_EXECUTION]: The skill relies on executing a local CLI binary (
~/.local/bin/granola) to perform meeting data retrieval and search operations.
Audit Metadata