coauthoring-docs

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process information from untrusted external sources, creating a potential surface for indirect prompt injection attacks.
  • Ingestion points: The workflow explicitly prompts for data from user info dumps, external shared documents (Google Drive, SharePoint), and team messaging channels (Slack, Teams) via platform integrations.
  • Boundary markers: There are no explicit instructions or delimiters provided to the agent to distinguish between its primary instructions and the untrusted content fetched from external sources.
  • Capability inventory: The skill utilizes the Write tool and the Edit tool to modify the local file system and invokes sub-agents to process and answer questions about the document content.
  • Sanitization: The skill lacks mechanisms for sanitizing or validating external content before it is processed by the agent or sub-agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:48 PM
Security Audit — agent-trust-hub — coauthoring-docs