pipa-budget-review

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest and analyze data from external, untrusted sources including SOWs, timesheets, and project management platforms like Jira, Linear, and Asana. This creates a surface for indirect prompt injection.
  • Ingestion points: Budget and delivery data from external tools referenced in SKILL.md.
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands are present.
  • Capability inventory: The skill is capable of performing file and external tool writes, which could be exploited, though it does require explicit user approval for each write.
  • Sanitization: No data sanitization or validation routines are specified.
  • [DATA_EXFILTRATION]: The skill instructions reference a local configuration file at ~/.pipa/communication-style.md. Accessing hidden configuration files in the home directory is a sensitive operation that could be leveraged for unauthorized data exposure if exploited.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 08:06 AM
Security Audit — agent-trust-hub — pipa-budget-review