comms
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process large volumes of untrusted data from diverse internal sources, creating a significant surface for injection attacks.
- Ingestion points: The instructions in
assets/examples/3p-updates.md,assets/examples/company-newsletter.md, andassets/examples/faq-answers.mdexplicitly direct the agent to ingest content from Slack channels, corporate emails, Google Drive documents, and calendar events. - Boundary markers: There are no delimiters or instructions provided to the agent to ignore or isolate potential commands embedded within the retrieved messages or documents.
- Capability inventory: The skill uses the ingested data to generate company-wide summaries, newsletters, and FAQs. A malicious Slack message or document could potentially manipulate these outputs to include phishing links or misleading instructions for the entire company.
- Sanitization: There is no mention of filtering, validation, or sanitization of the content retrieved from external tools before it is processed by the LLM.
Audit Metadata