doc-coauthoring

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it is designed to ingest and act upon data from untrusted external sources.
  • Ingestion points: During the Context Gathering stage, the skill instructions direct the agent to read external files, shared documents, and messaging threads (such as Slack or Teams) via integrations.
  • Boundary markers: The skill does not define specific delimiters or provide instructions to the agent to treat the ingested content strictly as data or to ignore any potential instructions found within that content.
  • Capability inventory: The skill leverages tools for creating and modifying files (create_file, str_replace) and retrieving information from connected organizational services.
  • Sanitization: There are no requirements or steps in the workflow to sanitize, validate, or filter the external content before it is incorporated into the document drafting process.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 12:07 PM
Security Audit — agent-trust-hub — doc-coauthoring