internal-comms

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection (Category 8). It is designed to ingest and summarize large volumes of untrusted data from Slack, Google Drive, and Email.
  • Ingestion points: Processes messages from Slack channels, Google Drive documents, and company-wide emails (referenced in examples/3p-updates.md, examples/company-newsletter.md, and examples/faq-answers.md).
  • Boundary markers: The instructions do not specify any delimiters or 'ignore embedded instructions' warnings when processing this external content.
  • Capability inventory: The agent uses tools to read personal and corporate data (Slack, Drive, Email, Calendar) and writes summaries based on that data.
  • Sanitization: No explicit sanitization or validation steps are mentioned to handle potentially malicious instructions embedded within the Slack posts or documents being summarized.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 04:33 PM
Security Audit — agent-trust-hub — internal-comms