internal-comms
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes data from external and shared internal environments without adequate isolation.\n
- Ingestion points: Multiple guideline files (examples/3p-updates.md, examples/company-newsletter.md, examples/faq-answers.md) direct the agent to consume content from Slack messages, Google Drive documents, corporate emails, and external press articles.\n
- Boundary markers: The instructions do not define boundary markers (such as XML tags or triple-backticks with headers) to separate retrieved data from the agent's core instructions, nor do they include warnings to ignore instructions found within that data.\n
- Capability inventory: The skill assumes and encourages the use of tools capable of reading sensitive corporate information and file storage systems.\n
- Sanitization: No sanitization or validation logic is provided to filter out potential adversarial commands or formatting from the ingested data before it is incorporated into the draft communications.
Audit Metadata