phoenix-orchestrator
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data such as Slack threads and customer notes to generate product specifications (documented in SKILL.md). This data flows through a multi-stage pipeline with capabilities to write to the local filesystem and export to external APIs (documented in SKILL.md). Ingestion points: User-uploaded raw context. Boundary markers: Absent. Capability inventory: File system writes to the outputs/ directory and network operations to Confluence, Slack, Linear, Asana, Notion, and Gmail. Sanitization: Absent.
- [DATA_EXFILTRATION]: The skill includes functionality to export generated content to third-party enterprise platforms including Confluence (using a specific Parent ID: 1273987073), Slack, Linear, Asana, Notion, and Gmail. These network operations are part of the defined post-pipeline connectors and target well-known services for project management and communication.
Audit Metadata