internal-comms
Pass
Audited by Gen Agent Trust Hub on May 9, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core function of ingesting and summarizing content from attacker-influenceable external sources such as Slack and Email.\n
- Ingestion points: Detailed in
examples/3p-updates.md,examples/company-newsletter.md, andexamples/faq-answers.md, which instruct the agent to use Slack, Email, Google Drive, and external press as information sources.\n - Boundary markers: Absent. The instructions do not provide delimiters or specific guidelines to help the agent differentiate between factual data and potential instructions embedded in the source materials.\n
- Capability inventory: The skill is restricted to gathering information and formatting text. It does not utilize capabilities for file modification, network exfiltration, or system command execution.\n
- Sanitization: No procedures for sanitizing, escaping, or validating the input data from external tools are defined in the workflow.
Audit Metadata