internal-comms

Pass

Audited by Gen Agent Trust Hub on May 9, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core function of ingesting and summarizing content from attacker-influenceable external sources such as Slack and Email.\n
  • Ingestion points: Detailed in examples/3p-updates.md, examples/company-newsletter.md, and examples/faq-answers.md, which instruct the agent to use Slack, Email, Google Drive, and external press as information sources.\n
  • Boundary markers: Absent. The instructions do not provide delimiters or specific guidelines to help the agent differentiate between factual data and potential instructions embedded in the source materials.\n
  • Capability inventory: The skill is restricted to gathering information and formatting text. It does not utilize capabilities for file modification, network exfiltration, or system command execution.\n
  • Sanitization: No procedures for sanitizing, escaping, or validating the input data from external tools are defined in the workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
May 9, 2026, 09:13 PM
Security Audit — agent-trust-hub — internal-comms