engagement-reporting

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill processes emails, chats, and transcripts which could contain untrusted instructions. The skill implements mitigations by instructing the agent to treat retrieved content as data only and to exclude suspected directives from reporting instructions.
  • Ingestion Points: External data is retrieved from communication platforms, project boards, and local transcript files.
  • Capabilities: The agent has the ability to write research findings to the local workspace and generate email drafts in connected mail services.
  • Sanitization: The instructions emphasize data minimization, the removal of credentials or tokens, and require explicit user approval before any draft creation.
  • Sensitive Data Storage: The skill generates unencrypted working artifacts in a local directory within the workspace. While the skill includes a mandatory data sensitivity notice and retention reminders, these files may contain confidential information or personal data retrieved during the research process.
  • Integrated Tool Usage: The skill interacts with external data retrieval and mail creation tools. The design includes safeguards such as requiring user confirmation for data access, acceptance of relevant terms of service, and strictly forbidding automated email transmission by restricting actions to draft creation only.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 04:30 AM
Security Audit — agent-trust-hub — engagement-reporting