relationship-debrief

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests meeting transcripts from ~/Documents/transcriptions/OpenOats/ to perform analysis. These transcripts are external data sources that could potentially contain malicious instructions intended to influence the agent's behavior. \n- Ingestion points: Transcripts stored in ~/Documents/transcriptions/OpenOats/. \n- Boundary markers: The skill differentiates between the meeting-notes region and the verbatim transcript, which provides some structural separation, though no explicit ignore instructions delimiters are used. \n- Capability inventory: The agent has the ability to read local team rosters and transcript files, and write new reports and CRM updates to the local filesystem. \n- Sanitization: There is no specific validation or sanitization of the transcript text to prevent embedded instructions from being interpreted by the LLM.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 10:16 PM
Security Audit — agent-trust-hub — relationship-debrief