pipa
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted external data to plan and track work, which presents an indirect prompt injection surface.
- Ingestion points: Untrusted data enters the agent context through lead notes, client message threads, and summaries of activity from external apps like Linear or GitHub.
- Boundary markers: The skill requires using 'TBD' for missing facts and returning explicit provenance (sources and owners) for all facts to mitigate hallucinations or injected claims.
- Capability inventory: The skill has the capability to write to external applications via 'composio-mcp' and schedule email reminders.
- Sanitization: The skill relies on schema checks at the tool execution level rather than explicit prompt-level sanitization or character escaping for ingested content.
Audit Metadata