meeting-minutes
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external content, which presents a surface for indirect prompt injection attacks.
- Ingestion points: External web pages (via context_dev_scrape_markdown tool), YouTube captions (via youtube_web_v2_video_captions tool), and raw transcripts or notes provided directly by the user in SKILL.md.
- Boundary markers: The operational workflow and prompt templates lack explicit boundary markers or instructions for the agent to ignore any embedded malicious commands within the source material.
- Capability inventory: The skill has the capability to generate content for external systems, including GitHub Issues and Jira, and can send drafts to external reviewers as described in the operational workflow.
- Sanitization: There are no instructions for sanitizing, filtering, or validating the ingested external content before it is used to generate the minutes or action items.
Audit Metadata