internal-comms-anthropic

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection attacks as it is designed to ingest and summarize data from untrusted sources such as Slack, Email, Google Drive, and external press. An attacker could embed malicious instructions in these communications to influence the agent's output.
  • Ingestion points: Slack messages, emails, Google Drive documents, Calendar events, and external press references as defined in the examples/ directory files.
  • Boundary markers: None identified; the instructions do not specify how to distinguish between data to be summarized and potential instructions within that data.
  • Capability inventory: The agent's capabilities are limited to generating internal communications (markdown/text). No file system access, command execution, or network exfiltration capabilities were identified.
  • Sanitization: No evidence of input validation or sanitization of external content before processing.
  • [NO_CODE]: The skill consists entirely of markdown instruction files and templates and does not include any executable code, scripts, or binary files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 11:36 AM
Security Audit — agent-trust-hub — internal-comms-anthropic