keel-cadence
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains an indirect prompt injection attack surface (Category 8).
- Ingestion points: Step 1 (Audit Current Meeting Load) requires the agent to read and analyze potentially untrusted external data such as meeting titles, descriptions, and participant lists.
- Boundary markers: The instructions do not provide delimiters or warnings to the agent to prevent it from obeying instructions that might be embedded within the meeting data being audited.
- Capability inventory: The skill is configured with access to high-privilege tools including
BashandWebFetch, which could be abused if the agent is influenced by malicious data. - Sanitization: There are no sanitization or validation steps to filter user-provided content before it is processed by the agent's logic.
Audit Metadata