attio-mcp-usage

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is composed entirely of Markdown files providing instructional content and does not include any scripts, binaries, or automated configuration files. No suspicious code or malicious commands were identified across the 17 files analyzed.
  • [PROMPT_INJECTION]: The skill outlines workflows that ingest data from external sources, identifying a surface for indirect prompt injection. This is a common characteristic of CRM automation skills.
  • Ingestion points: Data enters the system via CSV imports (resources/patterns/bulk-operations.md), external enrichment APIs such as Clearbit (resources/patterns/data-enrichment.md), and webhooks from form tools like Typeform or HubSpot (resources/patterns/revops-automation.md).
  • Boundary markers: The resources/golden-rules.md file recommends structural validation of UUIDs and data types, though it does not provide specific guidance for sanitizing natural language payloads within the CRM records.
  • Capability inventory: The patterns utilize standard Attio MCP tools including create-record, update-record, create-task, and create-note across all workflow scripts to process the ingested data.
  • Sanitization: Validation of attribute slugs and types is recommended throughout the guides as an error-prevention and data-integrity measure.
  • [DATA_EXFILTRATION]: The skill describes standard business processes for syncing data and sending notifications to well-known external services.
  • Evidence: Patterns in resources/patterns/revops-automation.md and resources/patterns/data-enrichment.md describe workflows involving Slack, Salesforce, HubSpot, and Zapier for operational automation. These are documented neutrally as standard integration targets.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 02:01 PM
Security Audit — agent-trust-hub — attio-mcp-usage