pipefy-process-intelligence
Pass
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by ingesting untrusted data from Pipefy cards via the
get_cardstool in SKILL.md. This data, which may contain user-provided text, is processed without explicit boundary markers or sanitization before the agent uses it to diagnose process gaps or execute configuration changes likecreate_automationorcreate_field_condition. While this presents a risk that adversarial instructions could influence the agent's behavior, it is a known and limited risk factor for this type of analytical skill.
Audit Metadata