pipa-manage

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill provides a feature to draft a business profile by reading content from a user-provided URL, which presents a surface for indirect prompt injection. \n
  • Ingestion points: Public website content accessed via user-provided URL in references/setup.md.\n
  • Boundary markers: Absent; instructions do not explicitly tell the agent to ignore instructions embedded in the website content.\n
  • Capability inventory: Ability to write to local configuration files (~/.pipa/profile.md, ~/.pipa/CONNECTORS.md) and execute tools via the composio-mcp toolkit.\n
  • Sanitization: Mitigation is present as the agent must obtain user confirmation before saving any proposed facts from external sources.\n- [SAFE]: No security issues were detected. The skill implements strong security practices by refusing to store credentials or secrets, instead relying on the composio-mcp service for authentication state. It also mandates user confirmation for actions that change external state, such as creating automations or connecting tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 08:06 AM
Security Audit — agent-trust-hub — pipa-manage