brief

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill scans untrusted external data such as emails and chat messages to generate briefings. This design introduces a surface where embedded instructions in those sources could potentially influence the agent's output.
  • Ingestion points: As noted in SKILL.md, the agent scans Email, Chat, and CRM data.
  • Boundary markers: The instructions do not specify delimiters or provide guidance to the agent on how to distinguish instructions from data within external sources.
  • Capability inventory: The skill uses tools to read from connected legal and communication platforms; it does not include instructions for writing to files or making external network requests.
  • Sanitization: The skill lacks explicit instructions for sanitizing or validating retrieved content before summarizing it for the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 11:27 PM
Security Audit — agent-trust-hub — brief