group-meeting-notes

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a productivity workflow for processing meeting information. It does not contain any executable code, obfuscation, or malicious instructions. It requires a pre-configured Yuque MCP server with appropriate tokens, following security best practices for credential management.
  • [PROMPT_INJECTION]: The skill processes untrusted meeting data (Category 8: Indirect Prompt Injection surface).
  • Ingestion points: User-provided meeting content processed in Step 1 of SKILL.md.
  • Boundary markers: Absent; content is formatted into a Markdown template without explicit delimiters or "ignore instructions" directives.
  • Capability inventory: yuque_list_repos and yuque_create_doc tools used for document creation.
  • Sanitization: Absent; the skill organizes input into a structured template but does not escape or validate content for embedded instructions. The risk is considered negligible given the intended use case.
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 09:11 AM
Security Audit — agent-trust-hub — group-meeting-notes