internal-comms-anthropic
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it directs the agent to process content from potentially untrusted or attacker-influenced sources.
- Ingestion points: Instructions in
examples/3p-updates.md,examples/company-newsletter.md, andexamples/faq-answers.mdtell the agent to gather data from Slack threads, Google Drive documents, emails, and external press releases. - Boundary markers: No specific delimiters or "ignore embedded instructions" directives are provided to help the agent distinguish between informational content and potential commands within the source data.
- Capability inventory: The skill leverages the agent's capabilities to search and read data across multiple workspace applications to generate summaries and drafts.
- Sanitization: The skill does not include steps for sanitizing, filtering, or validating the input gathered from these external tools before processing it.
Audit Metadata