triage
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external communication platforms.
- Ingestion points: The skill processes emails, Slack/Teams messages, and meeting action items (SKILL.md).
- Boundary markers: No explicit delimiters or instructions are provided to the agent to treat input as untrusted or to ignore instructions embedded within the data.
- Capability inventory: The guardrails mention that 'internal-to-team may send' messages, providing a communication capability that could be misused if the agent obeys instructions found in the triaged content.
- Sanitization: The instructions lack specific requirements for sanitizing or escaping the data before it is processed or used to generate next steps.
Audit Metadata