transcript-summarizer
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted meeting transcripts from various external formats including VTT, SRT, TXT, DOCX, and Google Docs. Malicious content within these transcripts could attempt to override the summarization instructions.
- Ingestion points: Processes transcripts from local directories (
REFLEX_TRANSCRIPT_SRC_DIR) and Google Workspace integration. - Boundary markers: The system prompt provided in the instructions does not use clear delimiters (like XML tags or triple quotes) or specific "ignore embedded instructions" directives to isolate untrusted data.
- Capability inventory: The skill writes original and processed transcripts to the local file system (
REFLEX_TRANSCRIPT_DST_DIR) and stores the final summary in a Qdrant vector database. - Sanitization: Preprocessing is focused on format cleanup (stripping timestamps and sequence numbers) but does not include sanitization of text for potentially malicious instructions.
- [EXTERNAL_DOWNLOADS]: The skill relies on external libraries for specific file format processing.
- Evidence: The documentation specifies extracting text from DOCX files using the
python-docxlibrary.
Audit Metadata