internal-comms
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill facilitates indirect prompt injection by instructing the agent to ingest untrusted data from various company communication tools.
- Ingestion points: The instruction files in the
examples/directory direct the agent to read content from Slack, Google Drive, and Email. - Boundary markers: No delimiters or safety instructions are provided to ensure that the agent treats retrieved content strictly as data.
- Capability inventory: The skill utilizes the agent's internal data access to generate high-visibility company communications, creating an exploitable surface.
- Sanitization: There is no guidance for filtering or validating the retrieved information before the agent processes it.
Audit Metadata