internal-comms

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its core functionality of ingesting and summarizing data from various external sources.
  • Ingestion points: The instructions in examples/3p-updates.md, examples/company-newsletter.md, and examples/faq-answers.md explicitly direct the agent to gather information from Slack messages, Google Drive documents, emails, and calendar events.
  • Boundary markers: There are no explicit instructions or delimiters provided to the agent to distinguish between its own system instructions and the content retrieved from external sources, nor are there warnings to ignore potentially malicious embedded instructions in that data.
  • Capability inventory: The skill primarily uses the agent's ability to read external data sources and generate text summaries. It does not appear to use subprocess calls or file-writing capabilities in the provided scripts.
  • Sanitization: The skill lacks any mention of sanitizing, escaping, or validating the content retrieved from Slack, email, or documents before processing it into internal communications.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — internal-comms