cowork-calendar-defrag

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes data from external sources.
  • Ingestion points: Reads meeting titles, descriptions, and agendas from Microsoft 365 and Google Calendar events as described in SKILL.md.
  • Boundary markers: No explicit instructions or delimiters are provided to the agent to distinguish between its system instructions and content within calendar events.
  • Capability inventory: The skill utilizes the Bash tool (shell command execution) and Write tool (file system access).
  • Sanitization: There is no evidence of filtering or sanitizing the content retrieved from calendar events before processing.
  • [COMMAND_EXECUTION]: The skill requests access to the Bash tool. While no specific malicious scripts are provided in the skill definition, the presence of this tool combined with the ingestion of untrusted external data creates a potential path for unintended command execution if the agent is manipulated via indirect injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 06:05 PM
Security Audit — agent-trust-hub — cowork-calendar-defrag