pipa-scope-baseline
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, exfiltration attempts, or unauthorized code execution sequences were detected. The skill instructions emphasize data integrity and human oversight.
- [COMMAND_EXECUTION]: The skill is configured to read local files in the
~/.pipa/directory (communication-style.mdandCONNECTORS.md) to personalize output style and determine tool preferences. This is a standard configuration pattern for this agent's ecosystem. - [PROMPT_INJECTION]: The skill ingests untrusted project data from external sources, which constitutes an indirect prompt injection surface. This risk is mitigated by an explicit safety workflow: 1) Ingestion points: project requirements and roadmaps from Jira, Notion, Slack, and Linear; 2) Boundary markers: explicit instructions to show planned changes and require user approval before writing; 3) Capability inventory: use of external tools via Composio MCP and local file discovery; 4) Sanitization: managed through mandatory human-in-the-loop verification.
- [PROMPT_INJECTION]: A defensive instruction is present that directs the agent to prioritize safety, tool use, and approval gates over presentation-layer instructions found in runtime configuration files.
Audit Metadata