pipa-ticket-triage
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill ingests untrusted data from intake sources such as meeting notes, chat messages, and email threads in SKILL.md. It does not utilize explicit boundary markers to isolate this intake data from its operational instructions. The skill has the capability to perform external writes to project management tools via composio-mcp, which are governed by a mandatory human-in-the-loop approval mechanism.
- [COMMAND_EXECUTION]: The skill contains instructions for performing external operations, including assigning owners and closing tickets in tracker tools. It effectively mitigates risk by requiring explicit user confirmation before any of these scoped actions are executed, preventing autonomous unauthorized changes.
Audit Metadata