doc-drafter

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill handles untrusted data from user briefs and external documents, which presents a surface for indirect prompt injection.
  • Ingestion points: User-provided briefs and reference documents accessed via the Google Drive connector.
  • Boundary markers: Safety Rule 7 explicitly instructs the agent to treat all briefs and reference documents as untrusted and to follow the user's direct instructions over any text found within the source material.
  • Capability inventory: The skill can write files to Google Drive and create document objects in PandaDoc.
  • Sanitization: The skill enforces the use of bracketed placeholders (e.g., [NEEDS: ...]) for any missing information, preventing the agent from following potentially malicious instructions embedded in data fields or hallucinating sensitive details.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 06:06 AM
Security Audit — agent-trust-hub — doc-drafter