performance-review-writer
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data which may contain hidden malicious instructions.
- Ingestion points: The skill ingests data from emails, chat messages, and meeting threads via the WorkIQ tool (SKILL.md, Step 2).
- Boundary markers: The instructions do not define clear boundaries or specify that the agent should ignore instructions embedded within the processed communications.
- Capability inventory: The skill has the ability to write files to the workspace (SKILL.md, Step 4).
- Sanitization: The skill contains instructions to redact personal details but lacks mechanisms to filter or sanitize potential prompt injection attacks contained within ingested messages.
- [COMMAND_EXECUTION]: The skill performs automated file system operations.
- Evidence: The skill is instructed to save final drafts to the workspace using a specific date-based folder convention (SKILL.md, Step 4).
Audit Metadata