meeting-briefing
Warn
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: MEDIUMPROMPT_INJECTIONDATA_EXFILTRATIONNO_CODE
Full Analysis
- [DATA_EXFILTRATION]: The skill instructs the agent to pull information from highly sensitive sources, including corporate Email, Chat (Slack, Teams), Documents (Box, SharePoint), and CLM/CRM systems. While this is the skill's primary purpose, the access to PII and privileged legal data is extensive.
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it processes untrusted data from external sources (Email, Chat) during the synthesis of briefings.
- Ingestion points: SKILL.md (Calendar, Email, Chat, Documents, CLM, CRM).
- Boundary markers: Absent; the instructions do not include delimiters or warnings to ignore embedded instructions in source data.
- Capability inventory: Implied read access to communication and document platforms.
- Sanitization: Absent; there are no instructions for sanitizing or validating external data.
- [NO_CODE]: This skill consists solely of instructions and templates in a Markdown file. No executable code or scripts are present.
Audit Metadata