legal-briefing
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and summarize data from various external systems which could potentially contain untrusted content.
- Ingestion points: Data is sourced from Calendar, Email, Messaging (Slack/Teams), and Document Repositories (SharePoint/Box) in Phase 3.
- Boundary markers: The skill does not define specific delimiters or instructions to ignore potential commands embedded within the retrieved messages or documents.
- Capability inventory: The skill's primary function is data aggregation and document generation. No commands for shell execution, local file modification, or external network exfiltration to unauthorized domains were found.
- Sanitization: There are no explicit requirements for sanitizing or escaping the content retrieved from external sources.
Audit Metadata