office-automation
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because its primary function involves processing untrusted external documents.
- Ingestion points: The skill reads and interprets content from local files including Word documents, Excel spreadsheets, and email templates (e.g.,
员工名单.xlsx,邮件模板.txt). - Boundary markers: The instructions do not define clear delimiters or provided specific directives for the agent to ignore instructions embedded within the data files it processes.
- Capability inventory: The agent has the ability to write to the local file system, generate reports, and send emails via SMTP, which could be misused if a document contains adversarial instructions.
- Sanitization: There is no mention of content filtering, sanitization, or validation for the data ingested from external files.
Audit Metadata