speaking

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from Gmail messages via gog gmail read and Google Sheets via gog sheets get which could contain malicious prompts.
  • Ingestion points: Email thread content and spreadsheet cell data are read into the agent context from SKILL.md.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions for the external data being processed to prevent the agent from following embedded instructions.
  • Capability inventory: The skill is authorized to update spreadsheets via gog sheets update and write to local files in the /Users/steipete/Projects/conferences/ directory.
  • Sanitization: There are no defined steps to sanitize or filter potential instructions embedded in the incoming communication data before it influences agent decisions or file writes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 11:27 PM
Security Audit — agent-trust-hub — speaking