pipa-keep-clients

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill's core functionalities, such as reading business context from a local profile (~/.pipa/profile.md) and integrating with CRM/Email services via Composio, are appropriate for its relationship management purpose. The instructions include explicit safeguards to prevent autonomous external actions.
  • [PROMPT_INJECTION]: The skill processes potentially untrusted data like client notes, support signals, and message threads, creating a surface for indirect prompt injection. This risk is effectively managed by strong boundary markers requiring human confirmation before any external actions (e.g., sending emails or updating records) are executed. Ingestion points: client notes and communication threads cited in references/keep-clients.md. Boundary markers: explicit 'Do not send' rules in both files. Capability inventory: email and CRM access via Composio and internal reminder tools. Sanitization: reliance on manual user review of all generated drafts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 08:06 AM
Security Audit — agent-trust-hub — pipa-keep-clients