speaking
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from Gmail messages via
gog gmail readand Google Sheets viagog sheets getwhich could contain malicious prompts. - Ingestion points: Email thread content and spreadsheet cell data are read into the agent context from
SKILL.md. - Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions for the external data being processed to prevent the agent from following embedded instructions.
- Capability inventory: The skill is authorized to update spreadsheets via
gog sheets updateand write to local files in the/Users/steipete/Projects/conferences/directory. - Sanitization: There are no defined steps to sanitize or filter potential instructions embedded in the incoming communication data before it influences agent decisions or file writes.
Audit Metadata