doc-coauthoring

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from various untrusted external sources, including Slack channels, Microsoft Teams threads, Google Drive/SharePoint documents, and user-provided files. If these external sources contain malicious instructions, they could influence the agent's behavior during the drafting or testing phases.
  • Ingestion points: The skill explicitly instructs the agent to fetch content from messaging apps, document storage, and shared links (Stage 1: Context Gathering).
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands within the fetched data are defined in the skill logic.
  • Capability inventory: The skill utilizes file creation and modification tools (create_file, str_replace) and can invoke sub-agents to process the document content.
  • Sanitization: There is no evidence of sanitization or filtering logic applied to external data before it is interpolated into the workflow or passed to sub-agents.
  • [COMMAND_EXECUTION]: The skill uses file system tools to manage document drafts, specifically create_file to initialize scaffolds and str_replace to perform surgical edits on sections. These capabilities are restricted to the document drafting process within the agent's working directory.
  • [EXTERNAL_DOWNLOADS]: The skill workflow involves fetching configuration and content from well-known services and trusted platforms such as Google Drive, Slack, and SharePoint via official integrations and MCP servers. These references are documented as part of the intended collaborative functionality and are accessed through established connection protocols.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:31 PM
Security Audit — agent-trust-hub — doc-coauthoring