internal-comms

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and summarize untrusted data from multiple company sources including Slack messages, emails, and shared documents (e.g., examples/3p-updates.md, examples/company-newsletter.md, examples/faq-answers.md). While this is the primary purpose of the skill, it lacks explicit boundary markers or instructions to the agent to ignore any embedded directives within that external content, creating a surface for indirect prompt injection.
  • Ingestion points: Slack, Email, Google Drive, and Calendar tools via multiple example guidelines.
  • Boundary markers: Absent. The instructions do not specify using delimiters or provide warnings to the agent about ignoring instructions found in the sourced data.
  • Capability inventory: The skill is primarily read-and-summarize; however, it has the ability to read from sensitive organizational silos (Email/Slack).
  • Sanitization: Not present.
  • [DATA_EXPOSURE]: The guidelines explicitly encourage the agent to look for sensitive information (e.g., "emails from executives," "fundraising," "hiring progress," "vision docs") to include in internal reports. While this is intended for internal use, there is a risk of accidental exposure if the agent's output is shared outside the intended audience, though this is mitigated by the skill's specific focus on internal communications.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 12:33 PM
Security Audit — agent-trust-hub — internal-comms