daily-prep
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to the aggregation of untrusted external content and workspace data into the agent context.
- Ingestion points: Meeting metadata (subject, organizer, attendee emails) retrieved from the WorkIQ tool, along with open tasks and workspace files.
- Boundary markers: Absent. The instructions do not define delimiters or direct the agent to treat data from the calendar or task files as untrusted text.
- Capability inventory: The skill possesses file system write capabilities, generating or modifying files under the
outputs/path. - Sanitization: Absent. There is no explicit mechanism detailed to escape or sanitize inputs before writing them to the self-contained HTML file.
Audit Metadata