doc-coauthoring

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by design, as it focuses on gathering context from untrusted external sources.
  • Ingestion points: In the 'Stage 1: Context Gathering' section of SKILL.md, the agent is instructed to read content from 'team channels or threads' and 'link to shared documents' using integrations (Slack, Teams, Google Drive, SharePoint).
  • Boundary markers: The skill lacks instructions to use delimiters or 'ignore' directives when interpolating retrieved external content into the agent's context, making it potentially vulnerable to instructions embedded within those documents.
  • Capability inventory: The agent has the capability to write and modify files using 'create_file' and 'str_replace', as specified in 'Stage 2: Refinement & Structure'.
  • Sanitization: No logic is present to sanitize, validate, or filter the content retrieved from external messaging or storage platforms before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 06:19 PM
Security Audit — agent-trust-hub — doc-coauthoring