attio-security-basics
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill involves analyzing local source code and official documentation, which creates a surface for potential indirect prompt injection should the analyzed data contain malicious instructions.\n
- Ingestion points: The skill utilizes
Read,Glob, andGrepto inspect local configuration and source files, andWebFetchto retrieve documentation from Attio's official developer portal.\n - Boundary markers: The analysis is guided by a detailed instruction set focused on security outcomes, although no explicit data delimiters are defined for the content processed.\n
- Capability inventory: The agent is granted
WriteandEditpermissions to apply remediation measures as part of the security hardening process.\n - Sanitization: The skill's primary function is to implement and verify sanitization protocols (such as log redaction) and validation (such as HMAC signature verification) for the Attio integration.\n- [SAFE]: No malicious patterns, unauthorized data exfiltration, or obfuscation techniques were detected. The skill adheres to security best practices and includes specific warnings against making unauthorized changes to production environments.
Audit Metadata