pipa-change-control

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions (in SKILL.md) include a protective meta-instruction that commands the agent to ignore presentation settings in external configuration files if they conflict with safety rules or approval gates. This is a positive security practice that prevents external data from overriding core safety constraints.
  • [DATA_EXFILTRATION]: Risks associated with data exfiltration or unauthorized file modification are mitigated by a mandatory human-in-the-loop rule (found in SKILL.md Rules) requiring separate, explicit approval for every external or file write operation. This approval must be scoped to the specific action, destination, and proposed content. The skill's read-only access to a project-specific style guide (~/.pipa/communication-style.md) does not involve sensitive data exposure and is consistent with the author's suite of tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 08:06 AM
Security Audit — agent-trust-hub — pipa-change-control