write-internal-doc

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process data from external collaborative platforms like Slack, Notion, GitHub, and Linear, which are potentially attacker-controlled sources.
  • Ingestion points: The skill ingests untrusted data from Slack messages, Notion pages, GitHub repositories, and Linear tickets to generate reports and documentation as specified in references/claims-and-sources.md and references/sharing-pass.md.
  • Boundary markers: The instructions mandate clear labeling of sources and the use of status words (e.g., "미확인" for unverified claims) but do not employ explicit boundary delimiters to isolate untrusted content from the agent's instructions.
  • Capability inventory: The skill has the capability to write to the local file system, perform Git operations (commit-and-push, draft-pr), and write to Notion via an MCP or plugin.
  • Sanitization: The skill includes a robust "Sharing Pass" mechanism (references/sharing-pass.md) specifically designed to strip credentials, confidential coordinates, and "working attack prompts or payloads" from the output, providing a significant defensive layer against malicious content propagation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 07:52 AM
Security Audit — agent-trust-hub — write-internal-doc