pipa-work-coordination
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface.\n
- Ingestion points: The skill ingests untrusted data from multiple external sources, including tracker boards, standup notes, Slack comments, Linear tickets, and GitHub repositories as identified in SKILL.md and evals.json.\n
- Boundary markers: The skill lacks explicit delimiters or instructions to ignore potentially malicious commands embedded in the processed work package notes or tool outputs.\n
- Capability inventory: The skill utilizes
composio-mcpfor reading from and writing to external tools. It also reads local configuration files from the~/.pipa/directory.\n - Sanitization: There is no evidence of sanitization or filtering of the data retrieved from external sources before it is processed and presented in the coordination report.\n- [NO_CODE]: The skill consists of markdown instructions and evaluation configurations but contains no executable code files, scripts, or binaries.
Audit Metadata