doc-coauthoring

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection during its context gathering phase. It instructs the agent to fetch and read content from external sources such as team channels, shared document links, and uploaded files. If these sources contain maliciously crafted instructions, they could influence the agent's behavior during the drafting or quality-testing stages.
  • Ingestion points: External content is fetched in Stage 1 from messaging integrations (Slack, Teams) and document storage (Google Drive, SharePoint, files).
  • Boundary markers: Absent; the skill lacks instructions for the agent to distinguish between administrative metadata and instructions versus the text meant to be processed as data.
  • Capability inventory: The skill utilizes file system tools (create_file, str_replace) to generate artifacts and invokes sub-agents to perform reader testing.
  • Sanitization: Absent; external context is interpolated directly into the brainstorming and drafting processes without validation or filtering.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 02:33 AM
Security Audit — agent-trust-hub — doc-coauthoring