skills/bsene/skills/communication/Gen Agent Trust Hub

communication

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external communication artifacts provided by the user, which presents a surface for indirect prompt injection.
  • Ingestion points: The skill explicitly analyzes Slack/Teams messages, emails, meeting transcripts, and pitch drafts as defined in the description and workflow (SKILL.md).
  • Boundary markers: The workflow instructs the agent to score and rewrite the artifact without defining delimiters or explicit instructions to treat the content solely as data, which could allow instructions embedded in the artifacts to influence agent behavior.
  • Capability inventory: The skill does not possess any dangerous capabilities; it has no defined tools, network access, file system write permissions, or shell execution capabilities.
  • Sanitization: The instructions do not specify any validation, filtering, or sanitization techniques for the content of the ingested artifacts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 04:26 PM
Security Audit — agent-trust-hub — communication