internal-comms

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data from various communication tools, creating a vulnerability to indirect prompt injection. * Ingestion points: The skill instructions in examples/3p-updates.md, examples/company-newsletter.md, and examples/faq-answers.md direct the agent to read content from Slack, Google Drive, Email, and Calendar. * Boundary markers: No specific boundary markers or instructions to treat ingested data as untrusted are included. * Capability inventory: The skill relies on tools to read messages, documents, and emails, and possesses the capability to generate and deliver formatted communications based on that data. * Sanitization: There is no requirement for sanitization or validation of the input data before it is processed by the LLM.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — internal-comms