internal-comms-anthropic

Pass

Audited by Gen Agent Trust Hub on Apr 13, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core workflow of processing untrusted data from multiple internal communication channels.\n
  • Ingestion points: The files examples/3p-updates.md, examples/company-newsletter.md, and examples/faq-answers.md instruct the agent to gather data from Slack messages, emails, Google Drive documents, and Calendar events.\n
  • Boundary markers: There are no explicit instructions or delimiters provided to the agent to distinguish between the skill's instructions and the content being retrieved from external sources.\n
  • Capability inventory: The skill encourages the agent to use its tool-access capabilities to read sensitive company communications and synthesize them into public-facing documents (newsletters, FAQs).\n
  • Sanitization: There are no guidelines provided for the agent to sanitize or validate the content retrieved from external tools before including it in the generated communication.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 13, 2026, 04:39 PM
Security Audit — agent-trust-hub — internal-comms-anthropic