internal-comms

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection because it is designed to ingest and summarize data from untrusted internal communication sources. \n
  • Ingestion points: Workplace tools including Slack, Email, and Google Drive (as specified in examples/3p-updates.md, examples/company-newsletter.md, and examples/faq-answers.md). \n
  • Boundary markers: There are no explicit instructions or delimiters used to separate the source data from the agent's core instructions. \n
  • Capability inventory: The agent's capabilities are limited to reading content and generating formatted text summaries. \n
  • Sanitization: No specific filtering or content validation logic is defined for the external data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 03:19 AM
Security Audit — agent-trust-hub — internal-comms