doc-coauthoring

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process information from untrusted external sources, which creates a vulnerability where malicious instructions embedded in those sources could influence agent behavior.
  • Ingestion points: The 'Context Gathering' stage in SKILL.md explicitly directs the agent to read user-uploaded files, shared document links, and content from messaging and storage integrations (e.g., Slack, Microsoft Teams, Google Drive, SharePoint).
  • Boundary markers: The instructions do not define explicit delimiters (e.g., XML tags or triple quotes) or 'ignore embedded instructions' warnings for the agent to use when interpolating external content into its working context.
  • Capability inventory: The skill utilizes file system manipulation tools (create_file, str_replace) to draft content and invokes sub-agents during the 'Reader Testing' stage, which could be influenced by malicious content gathered earlier.
  • Sanitization: There is no mention of sanitization, filtering, or validation of the text retrieved from external integrations or files before it is processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:52 PM
Security Audit — agent-trust-hub — doc-coauthoring