ai-meeting-assistant

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [NO_CODE]: The skill consists entirely of markdown documentation and instructional templates, with no executable scripts, binaries, or code files included.\n- [PROMPT_INJECTION]: The prompt templates provided for summarizing meetings and extracting action items ingest external transcription data, which presents a surface for indirect prompt injection.\n
  • Ingestion points: The 'Template: Prompt para Extração de Ações e Decisões' in SKILL.md uses a block to handle untrusted meeting data.\n
  • Boundary markers: The template employs XML-style tags () to delimit the input, which is a common but not foolproof mitigation against injection.\n
  • Capability inventory: The skill documentation describes workflows that send processed data to third-party tools like Slack, ClickUp, and CRM systems via automation platforms.\n
  • Sanitization: No specific instructions are provided for sanitizing or filtering the input transcripts to prevent embedded instructions from being followed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 12:37 AM
Security Audit — agent-trust-hub — ai-meeting-assistant