client-comms
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: Raw client feedback from calls, emails, and surveys in
references/feedback.md, as well as Git commit history, issue tickets, and deployment logs inreferences/factual-reporting.md. - Boundary markers: The instructions do not define specific delimiters or "ignore" instructions for the ingested content to prevent the agent from following commands embedded in the external data.
- Capability inventory: The skill is granted access to powerful system tools including
bash,run_command,write_to_file, andreplace_file_contentvia theagents/openai.yamlconfiguration. - Sanitization: There are no procedures defined for escaping, validating, or filtering external content before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill is configured to use tools like
bashandrun_commandto perform factual verification tasks. While these tools are used for legitimate purposes, such as checking Git SHAs or test receipts inreferences/factual-reporting.md, they represent a broad capability surface that could be exploited if the agent is compromised via prompt injection.
Audit Metadata