pipa-improve-operations

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill proactively addresses indirect prompt injection risks. In references/close-daily-shutdown.md, it mandates that retrieved records from ingestion points (project trackers, calendars, code hosting, chat, email) must be treated as untrusted data and never instructions. It explicitly directs the agent to ignore embedded requests to change behavior or reveal secrets, serving as a robust boundary marker.
  • [DATA_EXFILTRATION]: The skill accesses local configuration files (~/.pipa/profile.md and ~/.pipa/CONNECTORS.md) to establish business context and identify tool integrations. Analysis shows no evidence of these files or their contents being transmitted to external or unauthorized endpoints.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the Composio integration platform for discovering and interacting with external data sources. The instructions emphasize that these integrations are read-only by default and require separate, explicit user approval for any external writes or modifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 08:06 AM
Security Audit — agent-trust-hub — pipa-improve-operations