event-speaker-sourcing
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists entirely of instructional text and templates for an AI agent to perform speaker sourcing. It does not contain any executable scripts, shell commands, or network-enabled tools.\n- [SAFE]: The instructions include explicit security and privacy guardrails, such as forbidding bulk scraping, requiring the use of public channels, and prohibiting the targeting of candidates based on protected characteristics.\n- [INDIRECT_PROMPT_INJECTION]: The skill has a theoretical attack surface for indirect prompt injection as it instructs the agent to process data from external sources like community forums, mailing lists, and speaker directories. However, because the skill defines no capabilities for file writing, network exfiltration, or command execution, this surface poses no significant risk.\n
- Ingestion points: External sourcing channels such as community scouting and prior-talk review involve processing untrusted content from the web.\n
- Boundary markers: No specific delimiters are mandated for separating untrusted data from instructions.\n
- Capability inventory: No dangerous tools (shell, file-system, or network) are requested or used.\n
- Sanitization: No explicit sanitization logic is provided, which is typical for text-only analysis skills.\n- [SAFE]: All external references, such as Google, CNCF, and Speakerinnen, are well-known, trusted services or official vendor resources from samber.
Audit Metadata