pipefy-ai-agents

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill allows defining AI agents that process untrusted data and have significant operational capabilities, creating a surface for indirect prompt injection.\n- Ingestion points: Agents ingest data from card fields via placeholders, uploaded PDF documents, and pipe-scoped knowledge base sources.\n- Boundary markers: There are no specified boundary markers or instructions to isolate external data from the behavior's core instructions.\n- Capability inventory: Agents can be assigned actions like updating cards, moving cards, creating records, and sending emails, as well as advanced tools like web searching and scraping.\n- Sanitization: The instructions do not include requirements for sanitizing or validating ingested data before it is used by the agent behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 07:09 PM
Security Audit — agent-trust-hub — pipefy-ai-agents