written-communication

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by reading from and writing to local context files.
  • Ingestion points: The skill reads .agents/em-context.md and .agents/reports/[name].md to gather manager and employee context.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the ingestion logic.
  • Capability inventory: The skill possesses the ability to read and write files within the .agents/ directory.
  • Sanitization: There is no evidence of sanitization or filtering for content read from these files.
  • [EXTERNAL_DOWNLOADS]: The skill contains links to external articles for further reading.
  • Evidence: Links in references/sources.md point to newsletter.manager.dev.
  • Context: These resources belong to the vendor's official domain and are documented neutrally as intended educational material.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:46 AM
Security Audit — agent-trust-hub — written-communication