doc-coauthoring
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill has a functional surface for indirect prompt injection due to its reliance on ingesting large amounts of external, potentially untrusted text data.
- Ingestion points: The "Context Gathering" and "Info Dumping" sections in
SKILL.mdexplicitly instruct the agent to fetch and read content from shared documents, external files, and messaging integrations such as Slack or Teams. - Boundary markers: The skill does not define delimiters or use explicit instructions to separate the ingested data from its own core logic, which could result in the agent inadvertently executing commands hidden within the external content.
- Capability inventory: The agent is granted the ability to create and modify files using
create_fileandstr_replacebased on the context it gathers. - Sanitization: There is no requirement for sanitizing or validating the ingested content to identify or neutralize embedded instructions.
Audit Metadata