doc-coauthoring

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection attack surface as it is designed to ingest and process data from external sources.
  • Ingestion points: The skill reads content from external shared documents (e.g., Google Drive, SharePoint) and messaging platforms (e.g., Slack, Teams) via platform integrations.
  • Boundary markers: There are no explicit instructions or delimiters configured to prevent the agent from following instructions that might be embedded within the ingested external content.
  • Capability inventory: The skill possesses the capability to write and modify files using create_file and str_replace tools and can invoke sub-agents.
  • Sanitization: The instructions do not specify any sanitization or validation of external data before it is interpolated into the agent's drafting context.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the retrieval of information from well-known productivity services.
  • It mentions using integrations to fetch content from Google Drive, SharePoint, Slack, and Microsoft Teams to gather project context and document templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — doc-coauthoring