call-prep
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- Processing of External Content: The skill is designed to gather and synthesize information from external sources, including web searches for company news, leadership, and funding, as well as LinkedIn profiles and connected business tools like CRM and email. This is the core functionality of the skill, facilitating comprehensive meeting preparation.
- Indirect Prompt Injection Surface: By ingesting data from external sources, the skill creates a surface where instructions embedded in those sources (such as a web page or email) could potentially influence the agent.
- Ingestion points: Web search results, LinkedIn profile data, and content from connected CRM, Email, and Chat tools.
- Boundary markers: No specific delimiters or "ignore instructions" markers are explicitly defined in the execution flow for the synthesis step.
- Capability inventory: The skill relies on reading capabilities; there are no instances of command execution, file writing, or unauthorized network operations in the provided instructions.
- Sanitization: The instructions do not specify a sanitization process for the external data before it is presented in the final prep brief.
Audit Metadata