prism
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSMETADATA_POISONING
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were detected in the skill's instructions or logic. The skill operates as a high-level advisor and does not execute arbitrary code or interact with sensitive system resources.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external source materials including PDFs, Web URLs, and YouTube transcripts. While this creates a potential surface for indirect prompt injection, the skill includes explicit instructions to 'constrain to provided sources' and 'require explicit source grounding.' Furthermore, the agent lacks high-risk capabilities such as writing to the filesystem or executing shell commands, which limits the potential impact of such an attack to the generation of suboptimal prompt designs.
- [EXTERNAL_DOWNLOADS]: The skill references several official Google domains (blog.google, notebooklm.google, workspaceupdates.googleblog.com) to provide users with up-to-date information on tool limits and pricing. These are well-known, trusted sources and represent safe informational references.
- [METADATA_POISONING]: The skill uses future-dated metadata (e.g., created_at: '2026-04-25') and references features from 2026. While technically inaccurate in a current context, these appears to be a stylistic choice for a hypothetical future state of the product and do not pose a security threat or intent to deceive regarding safety protocols.
Audit Metadata