internal-comms
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill relies on ingesting data from external and internal communication channels, which exposes it to indirect prompt injection attacks.
- Ingestion points: Instructions in
examples/3p-updates.md,examples/company-newsletter.md, andexamples/faq-answers.mddirect the agent to gather context from Slack messages, emails, Google Drive documents, and Calendar events. - Boundary markers: The instructions do not define delimiters or provide specific prompts to the agent to disregard instructions found within the gathered source material.
- Capability inventory: The skill generates text for internal corporate distribution, such as newsletters, leadership updates, and status reports. While the skill files do not show direct system execution capabilities, the output is intended for consumption by employees and executives.
- Sanitization: There is no evidence of filtering, escaping, or validation logic applied to the content retrieved from the integrated tools.
Audit Metadata