pipefy-process-intelligence

Pass

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by ingesting untrusted data from Pipefy cards via the get_cards tool in SKILL.md. This data, which may contain user-provided text, is processed without explicit boundary markers or sanitization before the agent uses it to diagnose process gaps or execute configuration changes like create_automation or create_field_condition. While this presents a risk that adversarial instructions could influence the agent's behavior, it is a known and limited risk factor for this type of analytical skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 15, 2026, 04:54 PM
Security Audit — agent-trust-hub — pipefy-process-intelligence