internal-comms-anthropic

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it directs the agent to process content from potentially untrusted or attacker-influenced sources.
  • Ingestion points: Instructions in examples/3p-updates.md, examples/company-newsletter.md, and examples/faq-answers.md tell the agent to gather data from Slack threads, Google Drive documents, emails, and external press releases.
  • Boundary markers: No specific delimiters or "ignore embedded instructions" directives are provided to help the agent distinguish between informational content and potential commands within the source data.
  • Capability inventory: The skill leverages the agent's capabilities to search and read data across multiple workspace applications to generate summaries and drafts.
  • Sanitization: The skill does not include steps for sanitizing, filtering, or validating the input gathered from these external tools before processing it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 09:19 PM
Security Audit — agent-trust-hub — internal-comms-anthropic