twg-agentic-search
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
twgcommand-line tool to perform deep searches and fetch content from various enterprise applications. Commands includetwg rovo search,twg confluence content get, andtwg jira workitem get. This is standard functionality for interacting with the vendor's Teamwork Graph and Rovo services. - [PROMPT_INJECTION]: The skill ingests untrusted data from external sources such as Slack messages, Google Drive documents, and GitHub repositories. This creates a surface for indirect prompt injection. However, the skill provides specific rules to treat snippets as candidates rather than facts and requires verification across multiple primary sources, which mitigates the risk of the agent following malicious instructions embedded in the processed data.
Audit Metadata