share-internal-doc
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides comprehensive, professional guidelines for creating internal documents (reports, memos, handbooks). It prioritizes source traceability and reader accessibility without requesting unsafe tool access or executing suspicious commands.
- [DATA_EXPOSURE]: The skill includes robust safety instructions in
references/sharing-pass.mdandSKILL.mdto prevent accidental data leaks. It mandates stripping credentials, secrets, local file system paths (e.g.,/Users/,vscode://), and personally identifiable information (PII) before documents are shared. - [INDIRECT_PROMPT_INJECTION]: The skill defines an attack surface by ingesting data from external records (Slack, Notion, GitHub, and Linear) to generate reports. It mitigates this risk by requiring explicit boundary markers (e.g., the "reading rule" paragraph) and a sanitization pass that generalizes tool fingerprints and separates raw data from agent inferences.
- [COMMAND_EXECUTION]: While the instructions mention a build script for HTML generation and the use of the Notion MCP for publishing, the skill files contain no shell commands, script execution, or invocation of external binaries.
Audit Metadata