attio-security-basics

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill involves analyzing local source code and official documentation, which creates a surface for potential indirect prompt injection should the analyzed data contain malicious instructions.\n
  • Ingestion points: The skill utilizes Read, Glob, and Grep to inspect local configuration and source files, and WebFetch to retrieve documentation from Attio's official developer portal.\n
  • Boundary markers: The analysis is guided by a detailed instruction set focused on security outcomes, although no explicit data delimiters are defined for the content processed.\n
  • Capability inventory: The agent is granted Write and Edit permissions to apply remediation measures as part of the security hardening process.\n
  • Sanitization: The skill's primary function is to implement and verify sanitization protocols (such as log redaction) and validation (such as HMAC signature verification) for the Attio integration.\n- [SAFE]: No malicious patterns, unauthorized data exfiltration, or obfuscation techniques were detected. The skill adheres to security best practices and includes specific warnings against making unauthorized changes to production environments.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 01:10 PM
Security Audit — agent-trust-hub — attio-security-basics