flowhunt-skill

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core functionality of auditing external communication and task management tools.
  • Ingestion points: The skill explicitly directs the agent to scan content from Gmail, Google Calendar, Slack, and task trackers (Jira, Asana, Notion, Linear) to identify patterns.
  • Boundary markers: The instructions do not define delimiters or 'ignore embedded instructions' markers when processing data from these external sources in SKILL.md.
  • Capability inventory: The skill is designed for agents with access to broad toolsets (claude, codex, gemini, cursor), which may have permissions to read or write data based on the processed inputs.
  • Sanitization: There is no evidence of sanitization or validation protocols for external content before it is interpolated into the agent's analysis context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 07:57 AM
Security Audit — agent-trust-hub — flowhunt-skill