doc-coauthoring
Pass
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection because it is designed to ingest and process data from external sources such as shared documents, Slack channels, and Teams threads.\n
- Ingestion points: Shared document links, messaging platform channels (Slack, Teams), and cloud storage (Google Drive, SharePoint) via optional connectors mentioned in the instructions.\n
- Boundary markers: The instructions do not specify the use of delimiters or explicit warnings to the agent to ignore instructions embedded within the fetched external data.\n
- Capability inventory: The skill utilizes file-system tools like
create_fileandstr_replaceto generate and modify document artifacts based on the processed information.\n - Sanitization: There are no explicit sanitization, filtering, or validation steps defined for content retrieved from external integrations.
Audit Metadata