internal-comms
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection (Category 8). It is designed to ingest and summarize large volumes of untrusted data from Slack, Google Drive, and Email.
- Ingestion points: Processes messages from Slack channels, Google Drive documents, and company-wide emails (referenced in
examples/3p-updates.md,examples/company-newsletter.md, andexamples/faq-answers.md). - Boundary markers: The instructions do not specify any delimiters or 'ignore embedded instructions' warnings when processing this external content.
- Capability inventory: The agent uses tools to read personal and corporate data (Slack, Drive, Email, Calendar) and writes summaries based on that data.
- Sanitization: No explicit sanitization or validation steps are mentioned to handle potentially malicious instructions embedded within the Slack posts or documents being summarized.
Audit Metadata