writing-internal-comms

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted data from multiple communication channels.
  • Ingestion points: The skill processes content from Slack, Google Drive, emails, and calendars as defined in examples/3p-updates.md, examples/company-newsletter.md, and examples/faq-answers.md.
  • Boundary markers: The instructions do not define delimiters or specific rules to ensure the agent ignores instructions contained within the summarized content.
  • Capability inventory: The skill reads sensitive corporate data to generate internal communications like newsletters and FAQs.
  • Sanitization: No content filtering, validation, or escaping is performed on the ingested text to prevent instruction injection.
  • [METADATA_POISONING]: The LICENSE.txt file contains a copyright notice for 'Anthropic, PBC' and the year 2026, which is inconsistent with the skill's actual author and the current date, potentially misleading users about the skill's origin.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:49 PM
Security Audit — agent-trust-hub — writing-internal-comms