preparing-meeting-notes

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the GitHub CLI (gh) to retrieve details from Pull Requests and Issues, providing relevant context for upcoming meetings. This is a legitimate use of developer tooling.
  • [EXTERNAL_DOWNLOADS]: The skill retrieves data from well-known and trusted services including Microsoft 365, GitHub, and Slack to populate meeting notes. These operations are restricted to data retrieval and do not involve executing remote scripts.
  • [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes data from untrusted external sources.
  • Ingestion points: Meeting titles/descriptions from calendar sources, Slack thread messages, GitHub issue/PR content, and existing notes within the Obsidian vault.
  • Boundary markers: The instructions specify a structured Markdown layout for the notes, providing implicit boundaries for the ingested data.
  • Capability inventory: The skill has read/write access to the local Obsidian vault and read access to integrated developer tools.
  • Sanitization: The skill does not explicitly specify sanitization routines for the external data, though it instructs the agent to summarize the findings rather than directly executing instructions found within them.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 03:53 PM
Security Audit — agent-trust-hub — preparing-meeting-notes