daily-briefing
Pass
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: LOWPROMPT_INJECTIONNO_CODE
Full Analysis
- [Indirect Prompt Injection] (LOW): The skill is designed to ingest and prioritize content from untrusted external sources, creating a surface for indirect prompt injection.
- Ingestion points: The skill retrieves data from
Calendarevents (Step 1.1) andEmailpriority messages (Step 1.3). - Boundary markers: None provided; the workflow does not define delimiters or specific instructions to ignore embedded commands in the ingested data.
- Capability inventory: The skill uses the ingested data to perform 'Priority ranking' (Step 2), which influences the agent's internal reasoning and user-facing recommendations.
- Sanitization: There is no mention of sanitization, filtering, or validation of the content pulled from calendars or emails.
- [No Code Content] (INFO): The skill consists entirely of Markdown documentation and execution flow descriptions. It does not contain any executable scripts, binary files, or configuration files that would introduce runtime risks like RCE or exfiltration.
Audit Metadata