internal-comms
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to pull data from external, non-static sources such as Slack posts, emails, and shared documents. This creates a vulnerability where instructions embedded in those sources by other users could influence the agent's output or behavior.
- Ingestion points: Slack, Google Drive, Email, and Calendar as specified in the example files (e.g.,
examples/3p-updates.md). - Boundary markers: There are no instructions to the agent to distinguish between the content it is summarizing and potential instructions within that content.
- Capability inventory: The skill utilizes read-access tools for collaboration platforms to gather context for reports.
- Sanitization: The instructions do not include steps to sanitize or filter out malicious commands or formatting from the ingested data.
Audit Metadata