internal-comms

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to gather data from external communication platforms to compile internal updates, which presents an indirect prompt injection risk if the source channels contain adversarial inputs.\n
  • Ingestion points: Data is pulled from Slack messages, emails, Google Drive documents, calendar events, and external press as outlined in examples/3p-updates.md, examples/company-newsletter.md, and examples/faq-answers.md.\n
  • Boundary markers: Absent. No specific delimiters or instructions are provided to insulate the agent from commands embedded within the retrieved data.\n
  • Capability inventory: No executable scripts or tool configurations are supplied by the skill itself; it relies entirely on platform-level tool permissions.\n
  • Sanitization: Absent. There are no guidelines telling the agent to sanitize, escape, or filter out instructions found within external text.\n- [NO_CODE]: The skill repository contains only markdown templates, instructions, and standard text documentation without any code files, installation scripts, or software dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 10:59 PM
Security Audit — agent-trust-hub — internal-comms