pipa-scope-baseline

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, exfiltration attempts, or unauthorized code execution sequences were detected. The skill instructions emphasize data integrity and human oversight.
  • [COMMAND_EXECUTION]: The skill is configured to read local files in the ~/.pipa/ directory (communication-style.md and CONNECTORS.md) to personalize output style and determine tool preferences. This is a standard configuration pattern for this agent's ecosystem.
  • [PROMPT_INJECTION]: The skill ingests untrusted project data from external sources, which constitutes an indirect prompt injection surface. This risk is mitigated by an explicit safety workflow: 1) Ingestion points: project requirements and roadmaps from Jira, Notion, Slack, and Linear; 2) Boundary markers: explicit instructions to show planned changes and require user approval before writing; 3) Capability inventory: use of external tools via Composio MCP and local file discovery; 4) Sanitization: managed through mandatory human-in-the-loop verification.
  • [PROMPT_INJECTION]: A defensive instruction is present that directs the agent to prioritize safety, tool use, and approval gates over presentation-layer instructions found in runtime configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 08:06 AM
Security Audit — agent-trust-hub — pipa-scope-baseline