pipa-connectors
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill instructions emphasize security best practices, such as read-only discovery and explicit user approval for file writes. It uses a vendor-specific configuration path (~/.pipa/), minimizing impact on system files.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting external tool schemas and descriptions. 1. Ingestion points: Tool metadata fetched via composio-mcp in SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: File write access to ~/.pipa/CONNECTORS.md. 4. Sanitization: Not specified in instructions.
Audit Metadata