gws-workflow-meeting-prep

Pass

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill documentation instructs the agent to execute the "gws workflow +meeting-prep" command to fetch meeting agendas and attendee lists.\n- [SAFE]: The skill consists only of markdown instructions and does not contain any executable scripts, remote downloads, or persistence mechanisms.\n- [PROMPT_INJECTION]: The skill processes untrusted data from calendar events (descriptions and titles), which is a surface for indirect prompt injection. Ingestion points: Calendar event descriptions and linked document metadata processed via the "gws" tool. Boundary markers: No explicit delimiters are provided in the skill to separate data from instructions. Capability inventory: Limited to running the "gws" command for information retrieval. Sanitization: Not specified in the skill file.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 16, 2026, 03:09 PM