internal-comms
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by design. It instructs the agent to ingest and summarize untrusted data from Slack messages, Google Drive documents, and internal emails. Malicious actors within the organization could embed instructions in these sources (e.g., in Slack reactions or document comments) that target the agent's summarization logic.
- Ingestion points: Slack channels, Google Drive documents, and corporate Email threads mentioned in
examples/3p-updates.md,examples/company-newsletter.md, andexamples/faq-answers.md. - Boundary markers: None identified. The instructions lack clear delimiters (e.g., XML tags) or system-level directives to ignore embedded commands in the source material.
- Capability inventory: The skill primarily performs read operations on sensitive tools and generates text updates. While it does not explicitly call shell commands or network APIs beyond the provided tools, the generated output (newsletters/FAQs) is intended for company-wide distribution, potentially creating a downstream social engineering vector.
- Sanitization: There is no evidence of sanitization or filtering logic to strip potential injection strings from the gathered context before interpolation into the final report format.
Audit Metadata