writing-internal-comms
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted data from multiple communication channels.
- Ingestion points: The skill processes content from Slack, Google Drive, emails, and calendars as defined in examples/3p-updates.md, examples/company-newsletter.md, and examples/faq-answers.md.
- Boundary markers: The instructions do not define delimiters or specific rules to ensure the agent ignores instructions contained within the summarized content.
- Capability inventory: The skill reads sensitive corporate data to generate internal communications like newsletters and FAQs.
- Sanitization: No content filtering, validation, or escaping is performed on the ingested text to prevent instruction injection.
- [METADATA_POISONING]: The LICENSE.txt file contains a copyright notice for 'Anthropic, PBC' and the year 2026, which is inconsistent with the skill's actual author and the current date, potentially misleading users about the skill's origin.
Audit Metadata