internal-comms
Pass
Audited by Gen Agent Trust Hub on Mar 12, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [NO_CODE]: The skill is entirely documentation-based and contains no executable Python, JavaScript, or shell scripts.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface due to its data processing requirements.
- Ingestion points: Files
examples/3p-updates.md,examples/company-newsletter.md, andexamples/faq-answers.mddirect the agent to process content from Slack, Google Drive, Email, and Calendar. - Boundary markers: The templates lack specific instructions or delimiters to isolate processed data from the agent's core logic.
- Capability inventory: The skill facilitates the reading and summarization of internal enterprise communications.
- Sanitization: There are no defined procedures for validating or filtering the content retrieved from internal platforms before it is used to generate outputs.
Audit Metadata