pipa-work-coordination

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface.\n
  • Ingestion points: The skill ingests untrusted data from multiple external sources, including tracker boards, standup notes, Slack comments, Linear tickets, and GitHub repositories as identified in SKILL.md and evals.json.\n
  • Boundary markers: The skill lacks explicit delimiters or instructions to ignore potentially malicious commands embedded in the processed work package notes or tool outputs.\n
  • Capability inventory: The skill utilizes composio-mcp for reading from and writing to external tools. It also reads local configuration files from the ~/.pipa/ directory.\n
  • Sanitization: There is no evidence of sanitization or filtering of the data retrieved from external sources before it is processed and presented in the coordination report.\n- [NO_CODE]: The skill consists of markdown instructions and evaluation configurations but contains no executable code files, scripts, or binaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 08:06 AM
Security Audit — agent-trust-hub — pipa-work-coordination