wachi-producto

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from the external platform 'RumIAndo' using a dedicated MCP connector, which creates a surface for indirect prompt injection.
  • Ingestion points: The skill retrieves information using tools like resumen_producto, buscar_fichas, obtener_ficha, and actividad_filtrada.
  • Boundary markers: There are no defined delimiters or instructions to ignore potential commands within the external data.
  • Capability inventory: The skill possesses extensive write capabilities (e.g., guardar_ficha, transition_ficha, crear_ticket, crear_release) that could be misused if the agent is influenced by malicious data.
  • Sanitization: No specific validation or filtering logic for external content is implemented.
  • [EXTERNAL_DOWNLOADS]: The documentation instructs the user to configure an external MCP tool from https://rumiando.perennia.com.ar/mcp. This resource is associated with the vendor's infrastructure (perennia.com.ar) and is essential for the skill's operation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 04:39 PM
Security Audit — agent-trust-hub — wachi-producto