morning-brief

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external web searches and potentially shared internal sources (like calendar invites) which could contain malicious instructions designed to influence the agent's output.
  • Ingestion points: Data is ingested via a web search MCP, a calendar MCP, and a task list MCP.
  • Boundary markers: The instructions do not define specific delimiters or provide guidance to the model to ignore embedded commands within the ingested content.
  • Capability inventory: The agent has the capability to perform web searches and read from multiple sensitive data sources via MCPs.
  • Sanitization: There are no instructions for sanitizing, escaping, or filtering the external content before it is interpolated into the prompt context.
  • [DATA_EXPOSURE]: The skill is explicitly designed to handle highly sensitive user information, including calendar commitments, priority tasks, and potentially email content. While this is the intended functionality, access to these resources creates a high-value target for information exposure if the agent is compromised by external data.
  • [DATA_EXFILTRATION]: The execution flow requires the agent to pull data from internal sources and then perform a web search for named topics. This creates a functional path where sensitive internal entities, keywords, or project names could be leaked to third-party search engine providers as part of the search query generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 11:52 AM
Security Audit — agent-trust-hub — morning-brief