relationship-debrief
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests meeting transcripts from ~/Documents/transcriptions/OpenOats/ to perform analysis. These transcripts are external data sources that could potentially contain malicious instructions intended to influence the agent's behavior. \n- Ingestion points: Transcripts stored in ~/Documents/transcriptions/OpenOats/. \n- Boundary markers: The skill differentiates between the meeting-notes region and the verbatim transcript, which provides some structural separation, though no explicit ignore instructions delimiters are used. \n- Capability inventory: The agent has the ability to read local team rosters and transcript files, and write new reports and CRM updates to the local filesystem. \n- Sanitization: There is no specific validation or sanitization of the transcript text to prevent embedded instructions from being interpreted by the LLM.
Audit Metadata