internal-comms
Pass
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it instructs the agent to ingest and summarize information from untrusted sources such as Slack, Email, and Google Drive without defining security boundaries. * Ingestion points: Slack messages, emails, Google Drive documents, and Calendar events identified in examples/3p-updates.md, examples/company-newsletter.md, and examples/faq-answers.md. * Boundary markers: Absent. The instructions do not provide delimiters or 'ignore embedded instructions' warnings for the data being processed. * Capability inventory: The agent uses gathered data to generate summaries and lists of links, providing a vector for an attacker to inject malicious URLs or instructions into company-wide communications. * Sanitization: Absent. There is no guidance on validating or sanitizing content retrieved from the corporate tools.
Audit Metadata