meeting-coach-worker

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8) because it is designed to ingest and process raw, untrusted data such as meeting transcripts and work notes. An attacker or a malicious meeting participant could embed hidden instructions in the transcripts to manipulate the agent's coaching logic or readiness verdicts.
  • Ingestion points: SKILL.md instructs the agent to read the complete relevant corpus including raw transcripts, minutes, and work notes.
  • Boundary markers: The instructions lack specific delimiters or boundary markers to differentiate between the data being analyzed and the agent's own instructions.
  • Capability inventory: The agent is authorized to fork subagents for adversarial review and expectation reconstruction, providing a surface for multi-step injection effects.
  • Sanitization: No evidence of sanitization or instruction to ignore embedded commands was found in the skill files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 06:13 PM
Security Audit — agent-trust-hub — meeting-coach-worker