wachi-producto
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from the external platform 'RumIAndo' using a dedicated MCP connector, which creates a surface for indirect prompt injection.
- Ingestion points: The skill retrieves information using tools like
resumen_producto,buscar_fichas,obtener_ficha, andactividad_filtrada. - Boundary markers: There are no defined delimiters or instructions to ignore potential commands within the external data.
- Capability inventory: The skill possesses extensive write capabilities (e.g.,
guardar_ficha,transition_ficha,crear_ticket,crear_release) that could be misused if the agent is influenced by malicious data. - Sanitization: No specific validation or filtering logic for external content is implemented.
- [EXTERNAL_DOWNLOADS]: The documentation instructs the user to configure an external MCP tool from
https://rumiando.perennia.com.ar/mcp. This resource is associated with the vendor's infrastructure (perennia.com.ar) and is essential for the skill's operation.
Audit Metadata