enrich-from-transcript

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (transcripts from sources like Whisper, Granola, Otter) and uses it to modify existing notes or create new ones. This creates a surface where instructions hidden within a transcript could potentially influence the agent's behavior during the enrichment process.
  • Ingestion points: The skill reads transcripts end-to-end as primary input (SKILL.md).
  • Boundary markers: The instructions mention flagging corrupted passages or transcription artifacts but do not specify explicit delimiters or "ignore instructions" wrappers for the transcript content.
  • Capability inventory: The skill has the capability to edit existing notes in place or create new notes (SKILL.md).
  • Sanitization: There is no specific mention of sanitizing or escaping the content of transcripts to prevent injection, though there are instructions for the agent to verify interpretation with the user before committing changes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 09:00 PM