doc-coauthoring
Pass
Audited by Gen Agent Trust Hub on Feb 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious instructions, obfuscation, or unauthorized behaviors were detected. The skill's functionality is transparently directed toward assisting the user with documentation tasks.
- [EXTERNAL_DOWNLOADS]: The skill facilitates reading data from external platforms such as Google Drive, SharePoint, Slack, and Teams. These operations are conducted through official environment connectors and integrations for the legitimate purpose of gathering document context.
- [COMMAND_EXECUTION]: Uses the create_file and str_replace tools to manage the document drafting process. These operations are procedural, restricted to the workspace, and governed by user feedback.
- [PROMPT_INJECTION]: The skill ingests data from external documents and messaging threads, creating a surface for indirect prompt injection. Ingestion points: Shared files and team chat history read via integrations during Stage 1. Boundary markers: Not explicitly defined in the instructions. Capability inventory: File system modification (create_file, str_replace) and sub-agent invocation for testing. Sanitization: The workflow relies on iterative user review and curation (Stage 2) to filter content before finalization.
Audit Metadata