sales-meeting-recap

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data in the form of sales call notes and transcripts, which presents a surface for indirect prompt injection.\n
  • Ingestion points: The skill parses raw notes, transcripts, or descriptions supplied by the user as specified in Workflow Step 2 of SKILL.md.\n
  • Boundary markers: The instructions do not specify the use of delimiters or warnings to ignore instructions embedded in the provided notes.\n
  • Capability inventory: The skill drafts emails and potentially interacts with external CRM systems or calendar tools to log activities and book meetings (Workflow Steps 6 and 7).\n
  • Sanitization: No explicit sanitization or filtering mechanisms for external note content are described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:18 PM
Security Audit — agent-trust-hub — sales-meeting-recap