local-recurring-activity-planning

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted content from external websites and social media profiles to verify venue details and eligibility, creating a surface for indirect prompt injection. 1. Ingestion points: Official venue websites and booking systems (Workflow Step 4). 2. Boundary markers: Absent; there are no instructions to delimit or treat external content as untrusted. 3. Capability inventory: Uses web, browser, and calendar tools to create plans and outreach messages (Tools section). 4. Sanitization: Absent; no steps are provided to sanitize external content before it is interpolated into agent outputs.
  • [DATA_EXFILTRATION]: The skill accesses and processes sensitive user information, including precise home/work locations and calendar schedules. * Evidence: The workflow explicitly resolves the user's real origin from memory (Workflow Step 2) and checks multiple future weeks of calendar data for conflicts (Workflow Step 6). Although it instructs the agent not to repeat the address, the data is loaded into the context and used during network-based research, creating a potential exposure surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 04:50 PM
Security Audit — agent-trust-hub — local-recurring-activity-planning