internal-comms

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is specifically designed to ingest data from various external and potentially untrusted company sources, creating a significant attack surface for indirect prompt injection.
  • Ingestion points: The instructions in examples/3p-updates.md, examples/company-newsletter.md, and examples/faq-answers.md explicitly direct the agent to retrieve and process information from Slack messages, Google Drive documents, emails, and calendar events.
  • Boundary markers: The skill lacks any instructions to use delimiters or explicit warnings for the model to ignore instructions found within the retrieved external data, increasing the risk that embedded malicious commands could be executed.
  • Capability inventory: The agent uses the ingested data to perform summarization and content generation, which could be manipulated by an attacker who places instructions in a document or message that the agent is likely to read.
  • Sanitization: There are no requirements for sanitizing, filtering, or escaping the external content before it is interpolated into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:09 AM
Security Audit — agent-trust-hub — internal-comms