internal-comms
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data from various communication tools, creating a vulnerability to indirect prompt injection. * Ingestion points: The skill instructions in examples/3p-updates.md, examples/company-newsletter.md, and examples/faq-answers.md direct the agent to read content from Slack, Google Drive, Email, and Calendar. * Boundary markers: No specific boundary markers or instructions to treat ingested data as untrusted are included. * Capability inventory: The skill relies on tools to read messages, documents, and emails, and possesses the capability to generate and deliver formatted communications based on that data. * Sanitization: There is no requirement for sanitization or validation of the input data before it is processed by the LLM.
Audit Metadata