Skip to content
Report library
Purpose / Other

Internal Comms Skill Security Audit

What the author says it does (original text)

A set of resources to help me write all kinds of internal communications, using the formats that my company likes to use. Claude should use this skill whenever asked to write some sort of internal communications (status reports, leadership updates, 3P updates, company newsletters, FAQs, incident reports, project updates, etc.).

Independent security check

Security risks found

Files checked
6
Risks found
2
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.Risks found: 1
Medium risk

Broad collection across Slack, email, Drive, and calendars may pull sensitive internal material into drafts

Source references: 4
What we found

The guidelines direct the agent to pull from several company systems whenever possible and to gather as much context as it can. Selection is based mainly on reactions, views, replies, or perceived meeting importance—not sensitivity, a user-approved scope, or recipient authorization.

Why this matters

When those systems are connected, a draft may contain confidential project details, executive email content, meeting information, or internal document links. Later company-wide distribution could expose material beyond its original audience.

This is an active collection instruction, not merely an example: for a 3P update, the assistant is told to consult Slack, Google Drive, email, and calendars where possible and gather as much context as it can. If those connectors have broad authorization, sensitive high-engagement or high-view material could enter a draft intended for leaders or coworkers; the guidance does not filter by recipient access or confidentiality. It does not instruct automatic sending, and it asks the user when access is absent. Users can require explicit source scope, sensitivity exclusions, and human review before publication.

examples/3p-updates.md:14In the instructionsOpen original file
## Tools AvailableWhenever possible, try to pull from available sources to get the information you need:- Slack: posts from team members with their updates - ideally look for posts in large channels with lots of reactions- Google Drive: docs written from critical team members with lots of views- Email: emails with lots of responses of lots of content that seems relevant- Calendar: non-recurring meetings that have a lot of importance, like product reviews, etc.
Show 3 other places
examples/3p-updates.md:22In the instructionsOpen original file
Try to gather as much context as you can, focusing on the things that covered the time period you're writing for:- Progress: anything between a week ago and today- Plans: anything from today to the next week- Problems: anything between a week ago and todayIf you don't have access, you can ask the user for things they want to cover. They might also include these things to you directly, in which case you're mostly just formatting for this particular format.
examples/company-newsletter.md:12In the instructionsOpen original file
- Slack: look for messages in channels with lots of people, with lots of reactions or lots of responses within the thread- Email: look for things from executives that discuss company-wide announcements- Calendar: if there were meetings with large attendee lists, particularly things like All-Hands meetings, big company announcements, etc. If there were documents attached to those meetings, those are great links to include.- Documents: if there were new docs published in the last week or two that got a lot of attention, you can link them. These should be things like company-wide vision docs, plans for the upcoming quarter or half, things authored by critical executives, etc.- External press: if you see references to articles or press we've received over the past week, that could be really cool too.
examples/company-newsletter.md:2In the instructionsOpen original file
## InstructionsYou are being asked to write a company-wide newsletter update. You are meant to summarize the past week/month of a company in the form of a newsletter that the entire company will read. It should be maybe ~20-25 bullet points long. It will be sent via Slack and email, so make it consumable for that.
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.No risks found
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.No risks found
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.Risks found: 1
Medium risk

Inferring company facts from engagement and documents may produce unauthorized or misleading company-wide statements

Source references: 7
What we found

The newsletter guideline uses reactions, replies, and views as signals for what to feature, while the FAQ guideline permits questions to be inferred from document contents. It calls for uncertainty labels and prefers official communications, but does not require approval of final answers or company-level claims by an accountable owner.

Why this matters

Popular but unofficial, stale, or context-poor material could become a company-voice “we” statement or FAQ answer, affecting employee decisions about strategy, hiring, fundraising, launches, or similar matters.

The risk is supported, though the candidate combines two output types. The company newsletter selects material using reactions, replies, and document attention and is intended for Slack and email; the FAQ guidance also permits questions to be inferred from documents. If popularity is mistaken for truth or publication authorization, the result could be misleading or improperly disclosed company-wide. The FAQ safeguards—prefer official sources, mark uncertainty, and flag executive input—reduce but do not eliminate this risk because owner approval is not required. The source directs drafting, not automatic sending. Users can restrict inputs to approved sources and require content-owner sign-off.

examples/company-newsletter.md:5In the instructionsOpen original file
Ideally it includes the following attributes:- Lots of links: pulling documents from Google Drive that are very relevant, linking to prominent Slack messages in announce channels and from executives, perhgaps referencing emails that went company-wide, highlighting significant things that have happened in the company.- Short and to-the-point: each bullet should probably be no longer than ~1-2 sentences- Use the "we" tense, as you are part of the company. Many of the bullets should say "we did this" or "we did that"
Show 6 other places
examples/company-newsletter.md:12In the instructionsOpen original file
- Slack: look for messages in channels with lots of people, with lots of reactions or lots of responses within the thread- Email: look for things from executives that discuss company-wide announcements- Calendar: if there were meetings with large attendee lists, particularly things like All-Hands meetings, big company announcements, etc. If there were documents attached to those meetings, those are great links to include.- Documents: if there were new docs published in the last week or two that got a lot of attention, you can link them. These should be things like company-wide vision docs, plans for the upcoming quarter or half, things authored by critical executives, etc.- External press: if you see references to articles or press we've received over the past week, that could be really cool too.
examples/faq-answers.md:12In the instructionsOpen original file
You should use the company's available tools, where communication and work happens. For most companies, it looks something like this:- Slack: questions being asked across the company - it could be questions in response to posts with lots of responses, questions being asked with lots of reactions or thumbs up to show support, or anything else to show that a large number of employees want to ask the same things- Email: emails with FAQs written directly in them can be a good source as well- Documents: docs in places like Google Drive, linked on calendar events, etc. can also be a good source of FAQs, either directly added or inferred based on the contents of the doc
examples/faq-answers.md:25In the instructionsOpen original file
## Answer Guidelines- Base answers on official company communications when possible- If information is uncertain, indicate that clearly- Link to authoritative sources (docs, announcements, emails)- Keep tone professional but approachable- Flag if a question requires executive input or official response
examples/company-newsletter.md:2In the instructionsOpen original file
## InstructionsYou are being asked to write a company-wide newsletter update. You are meant to summarize the past week/month of a company in the form of a newsletter that the entire company will read. It should be maybe ~20-25 bullet points long. It will be sent via Slack and email, so make it consumable for that.Ideally it includes the following attributes:- Lots of links: pulling documents from Google Drive that are very relevant, linking to prominent Slack messages in announce channels and from executives, perhgaps referencing emails that went company-wide, highlighting significant things that have happened in the company.- Short and to-the-point: each bullet should probably be no longer than ~1-2 sentences
examples/company-newsletter.md:9In the instructionsOpen original file
## Tools to useIf you have access to the following tools, please try to use them. If not, you can also let the user know directly that their responses would be better if they gave them access.- Slack: look for messages in channels with lots of people, with lots of reactions or lots of responses within the thread- Email: look for things from executives that discuss company-wide announcements- Calendar: if there were meetings with large attendee lists, particularly things like All-Hands meetings, big company announcements, etc. If there were documents attached to those meetings, those are great links to include.- Documents: if there were new docs published in the last week or two that got a lot of attention, you can link them. These should be things like company-wide vision docs, plans for the upcoming quarter or half, things authored by critical executives, etc.- External press: if you see references to articles or press we've received over the past week, that could be really cool too.
examples/faq-answers.md:11In the instructionsOpen original file
## Tools AvailableYou should use the company's available tools, where communication and work happens. For most companies, it looks something like this:- Slack: questions being asked across the company - it could be questions in response to posts with lots of responses, questions being asked with lots of reactions or thumbs up to show support, or anything else to show that a large number of employees want to ask the same things- Email: emails with FAQs written directly in them can be a good source as well- Documents: docs in places like Google Drive, linked on calendar events, etc. can also be a good source of FAQs, either directly added or inferred based on the contents of the doc

Inside this skill

3 instruction sections

The Skill selects a guideline from examples/ based on the communication type, then follows that file’s formatting, tone, and information-gathering instructions.

View source
SKILL.md:21In the instructionsOpen original file
1. **Identify the communication type** from the request2. **Load the appropriate guideline file** from the `examples/` directory:    - `examples/3p-updates.md` - For Progress/Plans/Problems team updates    - `examples/company-newsletter.md` - For company-wide newsletters    - `examples/faq-answers.md` - For answering frequently asked questions    - `examples/general-comms.md` - For anything else that doesn't explicitly match one of the above3. **Follow the specific instructions** in that file for formatting, tone, and content gathering

The 3P guideline directs the agent to collect week-scoped information from Slack, Google Drive, email, and calendars; it asks the user only when access is unavailable.

View source
examples/3p-updates.md:14In the instructionsOpen original file
## Tools AvailableWhenever possible, try to pull from available sources to get the information you need:- Slack: posts from team members with their updates - ideally look for posts in large channels with lots of reactions- Google Drive: docs written from critical team members with lots of views- Email: emails with lots of responses of lots of content that seems relevant- Calendar: non-recurring meetings that have a lot of importance, like product reviews, etc.
examples/3p-updates.md:22In the instructionsOpen original file
Try to gather as much context as you can, focusing on the things that covered the time period you're writing for:- Progress: anything between a week ago and today- Plans: anything from today to the next week- Problems: anything between a week ago and todayIf you don't have access, you can ask the user for things they want to cover. They might also include these things to you directly, in which case you're mostly just formatting for this particular format.

The company newsletter is designed as roughly 20–25 bullets for company-wide consumption over Slack and email, and the guideline encourages links to internal documents, messages, and emails.

View source
examples/company-newsletter.md:2In the instructionsOpen original file
## InstructionsYou are being asked to write a company-wide newsletter update. You are meant to summarize the past week/month of a company in the form of a newsletter that the entire company will read. It should be maybe ~20-25 bullet points long. It will be sent via Slack and email, so make it consumable for that.
examples/company-newsletter.md:4In the instructionsOpen original file
Ideally it includes the following attributes:- Lots of links: pulling documents from Google Drive that are very relevant, linking to prominent Slack messages in announce channels and from executives, perhgaps referencing emails that went company-wide, highlighting significant things that have happened in the company.- Short and to-the-point: each bullet should probably be no longer than ~1-2 sentences- Use the "we" tense, as you are part of the company. Many of the bullets should say "we did this" or "we did that"

The FAQ guideline seeks widely shared questions through company tools and permits FAQs to be inferred from documents, while requiring uncertainty to be stated and official communications to be preferred.

View source
examples/faq-answers.md:10In the instructionsOpen original file
## Tools AvailableYou should use the company's available tools, where communication and work happens. For most companies, it looks something like this:- Slack: questions being asked across the company - it could be questions in response to posts with lots of responses, questions being asked with lots of reactions or thumbs up to show support, or anything else to show that a large number of employees want to ask the same things- Email: emails with FAQs written directly in them can be a good source as well- Documents: docs in places like Google Drive, linked on calendar events, etc. can also be a good source of FAQs, either directly added or inferred based on the contents of the doc
examples/faq-answers.md:25In the instructionsOpen original file
## Answer Guidelines- Base answers on official company communications when possible- If information is uncertain, indicate that clearly- Link to authoritative sources (docs, announcements, emails)- Keep tone professional but approachable- Flag if a question requires executive input or official response
Start here · InstructionsSKILL.md
internal-comms
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source.

File reference map

References: 1
Files making referencesReferenced content
Lines show actual file references, not execution order. Select a node to highlight its connections and inspect the files and source locations. Dashed lines include files that still need locating.
Files and check records6 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included
  • LICENSE.txtFull text included
  • examples/3p-updates.mdFull text included
  • examples/company-newsletter.mdFull text included
  • examples/faq-answers.mdFull text included
  • examples/general-comms.mdFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • LICENSE.txtLicense
  • SKILL.mdInstructions
  • examples/3p-updates.mdSupporting file
  • examples/company-newsletter.mdSupporting file
  • examples/faq-answers.mdSupporting file
  • examples/general-comms.mdSupporting file
Lines read
394
File checksum (to compare versions)
d99fbc59afe383cbdd73584613009c1c05d29a5f4aa0abdcfab54ac2dfde4b6c