pipa-connectors

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill instructions emphasize security best practices, such as read-only discovery and explicit user approval for file writes. It uses a vendor-specific configuration path (~/.pipa/), minimizing impact on system files.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting external tool schemas and descriptions. 1. Ingestion points: Tool metadata fetched via composio-mcp in SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: File write access to ~/.pipa/CONNECTORS.md. 4. Sanitization: Not specified in instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 08:06 AM
Security Audit — agent-trust-hub — pipa-connectors