internal-comms

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill contains no executable code, network operations, or hardcoded credentials. Its functionality is limited to guiding text generation based on local templates.\n- [NO_CODE]: The skill consists entirely of markdown instructions and license documentation with no associated scripts or binaries.\n- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to load and follow instructions from external files in the examples/ directory (e.g., examples/3p-updates.md). This creates a surface for indirect prompt injection if the referenced files were to contain malicious instructions. However, no malicious content was found in the provided files.\n
  • Ingestion points: examples/3p-updates.md, examples/company-newsletter.md, examples/faq-answers.md, examples/general-comms.md (referenced in SKILL.md)\n
  • Boundary markers: Absent. No specific delimiters or warnings are used when loading these instructions.\n
  • Capability inventory: No technical capabilities like file writing, network access, or command execution are present in the analyzed files.\n
  • Sanitization: Absent. The agent is instructed to follow instructions in those files directly.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 08:18 AM
Security Audit — agent-trust-hub — internal-comms