doc-coauthoring

Pass

Audited by Gen Agent Trust Hub on Apr 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a procedural workflow for document creation that aligns with its stated purpose. It uses standard tools for file manipulation (create_file, str_replace) and document structure management.
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it processes external context from sources like Slack and Google Drive. 1. Ingestion points: Integration with communication and storage platforms (Slack, Teams, Google Drive, SharePoint). 2. Boundary markers: The instructions do not define specific delimiters for separating fetched external data from instructions. 3. Capability inventory: The skill utilizes file creation, string replacement, and sub-agent invocation. 4. Sanitization: No explicit content validation or sanitization is performed on external data. This surface is considered safe given the skill's role as a writing assistant where the user maintains agency over curation and refinement.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 8, 2026, 10:20 AM
Security Audit — agent-trust-hub — doc-coauthoring