doc-coauthoring

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection because it is designed to ingest and process data from external sources such as shared documents, Slack channels, and Teams threads.\n
  • Ingestion points: Shared document links, messaging platform channels (Slack, Teams), and cloud storage (Google Drive, SharePoint) via optional connectors mentioned in the instructions.\n
  • Boundary markers: The instructions do not specify the use of delimiters or explicit warnings to the agent to ignore instructions embedded within the fetched external data.\n
  • Capability inventory: The skill utilizes file-system tools like create_file and str_replace to generate and modify document artifacts based on the processed information.\n
  • Sanitization: There are no explicit sanitization, filtering, or validation steps defined for content retrieved from external integrations.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 03:22 PM
Security Audit — agent-trust-hub — doc-coauthoring