internal-comms

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it instructs the agent to ingest and summarize information from untrusted sources such as Slack, Email, and Google Drive without defining security boundaries. * Ingestion points: Slack messages, emails, Google Drive documents, and Calendar events identified in examples/3p-updates.md, examples/company-newsletter.md, and examples/faq-answers.md. * Boundary markers: Absent. The instructions do not provide delimiters or 'ignore embedded instructions' warnings for the data being processed. * Capability inventory: The agent uses gathered data to generate summaries and lists of links, providing a vector for an attacker to inject malicious URLs or instructions into company-wide communications. * Sanitization: Absent. There is no guidance on validating or sanitizing content retrieved from the corporate tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 03:20 PM
Security Audit — agent-trust-hub — internal-comms