internal-comms
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION] (LOW): The skill is susceptible to Indirect Prompt Injection (Category 8) due to the ingestion of untrusted data from multiple sources.
- Ingestion points: Guidelines in
examples/3p-updates.md,examples/company-newsletter.md, andexamples/faq-answers.mddirect the agent to process data from Slack, Google Drive, Email, and External Press. - Boundary markers: None provided to separate instructions from untrusted data.
- Capability inventory: Extensive read access to organizational communication tools and data stores.
- Sanitization: No instructions for sanitizing or escaping ingested content before summarization.
Audit Metadata