meeting-follow-up-coach

Fail

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: CRITICALPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it processes untrusted meeting transcripts to generate summaries and emails.
  • Ingestion points: Meeting transcripts or notes (SKILL.md).
  • Boundary markers: Absent; the skill does not use delimiters or warnings to ignore instructions within transcripts.
  • Capability inventory: Drafting emails and proposing CRM updates.
  • Sanitization: Absent; input text is processed directly.
  • [EXTERNAL_DOWNLOADS]: The domain 'Builder.org' specified in the author metadata was flagged as malicious by automated scanners. While no executable code for downloading content was found, the presence of a blacklisted domain in the metadata is a reputation risk.
Recommendations
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 4, 2026, 04:37 PM
Security Audit — agent-trust-hub — meeting-follow-up-coach