legal-briefing
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process and summarize content from external sources which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: The 'Phase 3: Assemble Context' section of
SKILL.mddirects the agent to gather data from Email Systems, Messaging Platforms (Slack, Teams), and Document Repositories (SharePoint, Box, Egnyte). - Boundary markers: The briefing instructions do not include specific delimiters or directives to the agent to ignore or isolate instructions that may be embedded within the gathered external content.
- Capability inventory: No executable scripts are provided within the skill itself, but the instructions assume the agent has access to integrated tools for reading private and external communication channels.
- Sanitization: The workflow lacks explicit steps for sanitizing, filtering, or validating the content retrieved from these external systems before it is incorporated into the briefing document.
Audit Metadata