transcript-summarizer

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted meeting transcripts from various external formats including VTT, SRT, TXT, DOCX, and Google Docs. Malicious content within these transcripts could attempt to override the summarization instructions.
  • Ingestion points: Processes transcripts from local directories (REFLEX_TRANSCRIPT_SRC_DIR) and Google Workspace integration.
  • Boundary markers: The system prompt provided in the instructions does not use clear delimiters (like XML tags or triple quotes) or specific "ignore embedded instructions" directives to isolate untrusted data.
  • Capability inventory: The skill writes original and processed transcripts to the local file system (REFLEX_TRANSCRIPT_DST_DIR) and stores the final summary in a Qdrant vector database.
  • Sanitization: Preprocessing is focused on format cleanup (stripping timestamps and sequence numbers) but does not include sanitization of text for potentially malicious instructions.
  • [EXTERNAL_DOWNLOADS]: The skill relies on external libraries for specific file format processing.
  • Evidence: The documentation specifies extracting text from DOCX files using the python-docx library.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 08:36 PM