pipa-budget-review
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and analyze data from external, untrusted sources including SOWs, timesheets, and project management platforms like Jira, Linear, and Asana. This creates a surface for indirect prompt injection.
- Ingestion points: Budget and delivery data from external tools referenced in SKILL.md.
- Boundary markers: No specific delimiters or instructions to ignore embedded commands are present.
- Capability inventory: The skill is capable of performing file and external tool writes, which could be exploited, though it does require explicit user approval for each write.
- Sanitization: No data sanitization or validation routines are specified.
- [DATA_EXFILTRATION]: The skill instructions reference a local configuration file at ~/.pipa/communication-style.md. Accessing hidden configuration files in the home directory is a sensitive operation that could be leveraged for unauthorized data exposure if exploited.
Audit Metadata