coauthoring-docs
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process information from untrusted external sources, creating a potential surface for indirect prompt injection attacks.
- Ingestion points: The workflow explicitly prompts for data from user info dumps, external shared documents (Google Drive, SharePoint), and team messaging channels (Slack, Teams) via platform integrations.
- Boundary markers: There are no explicit instructions or delimiters provided to the agent to distinguish between its primary instructions and the untrusted content fetched from external sources.
- Capability inventory: The skill utilizes
the Write toolandthe Edit toolto modify the local file system and invokes sub-agents to process and answer questions about the document content. - Sanitization: The skill lacks mechanisms for sanitizing or validating external content before it is processed by the agent or sub-agents.
Audit Metadata