comms

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process large volumes of untrusted data from diverse internal sources, creating a significant surface for injection attacks.
  • Ingestion points: The instructions in assets/examples/3p-updates.md, assets/examples/company-newsletter.md, and assets/examples/faq-answers.md explicitly direct the agent to ingest content from Slack channels, corporate emails, Google Drive documents, and calendar events.
  • Boundary markers: There are no delimiters or instructions provided to the agent to ignore or isolate potential commands embedded within the retrieved messages or documents.
  • Capability inventory: The skill uses the ingested data to generate company-wide summaries, newsletters, and FAQs. A malicious Slack message or document could potentially manipulate these outputs to include phishing links or misleading instructions for the entire company.
  • Sanitization: There is no mention of filtering, validation, or sanitization of the content retrieved from external tools before it is processed by the LLM.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:50 PM