comms-update

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the latest version of the @agentcomms/core package from the npm registry using npx to ensure the core infrastructure is current.
  • [COMMAND_EXECUTION]: Executes administrative commands like agentcomms update and mcp prune to manage server lifecycles and clean up orphaned files after updates.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates on data from external messaging platforms (Gmail and Slack) which creates a surface for indirect instructions.
  • Ingestion points: Gmail and Slack account content.
  • Boundary markers: Human approval required via approvalId for all configuration changes.
  • Capability inventory: Use of npx and local CLI tools (agentcomms, agent-slack).
  • Sanitization: The core skills contract mandates treating account content strictly as data and never as instructions.
  • [SAFE]: Implements secure handling of credentials by explicitly prohibiting the display or logging of secrets, tokens, or configuration keys.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 12:33 AM
Security Audit — agent-trust-hub — comms-update