conference-meeting-cards
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from multiple external sources which introduces a potential surface for indirect prompt injection. Malicious instructions embedded in these external sources could attempt to manipulate the generated summaries or the agent's behavior.
- Ingestion points: The skill reads data from CRM account records (HubSpot, Salesforce, etc.), LinkedIn profiles via enrichment or profile fetches, company websites for 'what they do' summaries, and external meeting notes tools (e.g., Circleback, Gong, Fireflies).
- Boundary markers: The instructions do not specify the use of delimiters or 'ignore instructions' warnings when interpolating the retrieved external content into the meeting cards.
- Capability inventory: The skill has the capability to write to the file system (in the specified
{{OUTPUT_FOLDER}}), perform network-based enrichment, and send direct messages (DMs) via the agent platform. - Sanitization: No specific sanitization, validation, or escaping of the retrieved external text is mentioned in the instructions before it is rendered into the final HTML output.
- [DATA_EXFILTRATION]: The skill collects sensitive business intelligence, including deal amounts, internal stages, and forecast risks from a CRM, and stores it in an HTML file. It then generates an 'unguessable, expiring share link' for this file. While the skill mandates that links be sent via DM to specific team members, the creation of public-facing links for internal deal data represents a potential data exposure risk if the platform's link security or expiration mechanisms are weak.
Audit Metadata