NYC

internal-comms

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION] (LOW): The skill is susceptible to Indirect Prompt Injection (Category 8) due to the ingestion of untrusted data from multiple sources.
  • Ingestion points: Guidelines in examples/3p-updates.md, examples/company-newsletter.md, and examples/faq-answers.md direct the agent to process data from Slack, Google Drive, Email, and External Press.
  • Boundary markers: None provided to separate instructions from untrusted data.
  • Capability inventory: Extensive read access to organizational communication tools and data stores.
  • Sanitization: No instructions for sanitizing or escaping ingested content before summarization.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:18 PM