pipa-manage
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill provides a feature to draft a business profile by reading content from a user-provided URL, which presents a surface for indirect prompt injection. \n
- Ingestion points: Public website content accessed via user-provided URL in references/setup.md.\n
- Boundary markers: Absent; instructions do not explicitly tell the agent to ignore instructions embedded in the website content.\n
- Capability inventory: Ability to write to local configuration files (~/.pipa/profile.md, ~/.pipa/CONNECTORS.md) and execute tools via the composio-mcp toolkit.\n
- Sanitization: Mitigation is present as the agent must obtain user confirmation before saving any proposed facts from external sources.\n- [SAFE]: No security issues were detected. The skill implements strong security practices by refusing to store credentials or secrets, instead relying on the composio-mcp service for authentication state. It also mandates user confirmation for actions that change external state, such as creating automations or connecting tools.
Audit Metadata