internal-comms

Pass

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes data from external and shared internal environments without adequate isolation.\n
  • Ingestion points: Multiple guideline files (examples/3p-updates.md, examples/company-newsletter.md, examples/faq-answers.md) direct the agent to consume content from Slack messages, Google Drive documents, corporate emails, and external press articles.\n
  • Boundary markers: The instructions do not define boundary markers (such as XML tags or triple-backticks with headers) to separate retrieved data from the agent's core instructions, nor do they include warnings to ignore instructions found within that data.\n
  • Capability inventory: The skill assumes and encourages the use of tools capable of reading sensitive corporate information and file storage systems.\n
  • Sanitization: No sanitization or validation logic is provided to filter out potential adversarial commands or formatting from the ingested data before it is incorporated into the draft communications.
Audit Metadata
Risk Level
SAFE
Analyzed
May 6, 2026, 02:09 PM
Security Audit — agent-trust-hub — internal-comms