doc-coauthoring
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by design, as it focuses on gathering context from untrusted external sources.
- Ingestion points: In the 'Stage 1: Context Gathering' section of SKILL.md, the agent is instructed to read content from 'team channels or threads' and 'link to shared documents' using integrations (Slack, Teams, Google Drive, SharePoint).
- Boundary markers: The skill lacks instructions to use delimiters or 'ignore' directives when interpolating retrieved external content into the agent's context, making it potentially vulnerable to instructions embedded within those documents.
- Capability inventory: The agent has the capability to write and modify files using 'create_file' and 'str_replace', as specified in 'Stage 2: Refinement & Structure'.
- Sanitization: No logic is present to sanitize, validate, or filter the content retrieved from external messaging or storage platforms before processing.
Audit Metadata