pipa-deliver-work

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest and process content from external, untrusted sources including project trackers (Jira, Linear) and communication platforms (Slack, email) for status monitoring and ticket triage. This creates a surface for indirect prompt injection.
  • Ingestion points: Data is pulled from external integrations and meeting notes as specified in references/monitor-status.md and references/monitor-ticket-triage.md.
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore commands within the ingested content.
  • Capability inventory: The agent uses the composio toolset for application integration and produces text-based coordination summaries and response drafts.
  • Sanitization: No explicit sanitization or filtering of external input is described in the provided workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 08:06 AM
Security Audit — agent-trust-hub — pipa-deliver-work