pre-meeting-brief
Fail
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: CRITICALPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection due to its ingestion of untrusted data from external sources. Malicious instructions embedded in web pages or HubSpot notes could potentially influence the agent's briefing or objectives. * Ingestion points: HubSpot engagement notes and external web search results (Workflow steps 2 and 3). * Boundary markers: The instructions do not define delimiters or explicit warnings to the model to ignore instructions within the retrieved data. * Capability inventory: The skill is primarily read-only, which mitigates the risk of the injection triggering unauthorized actions. * Sanitization: There is no process described for validating or cleaning the external content before it is processed by the AI.
Recommendations
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata