pipa-triggers

Warn

Audited by Socket on Jul 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities mostly match its purpose, and it includes sensible confirmation/scope controls. The main risk is that it reads runtime secrets and routes all trigger-management data through a Pipa gateway whose public ownership/API documentation is not strongly verifiable, while enabling persistent real-world automations with future external actions.

Confidence: 83%Severity: 58%
Audit Metadata
Analyzed At
Jul 23, 2026, 09:04 PM
Package URL
pkg:socket/skills-sh/lunchpaillola%2Fpipa-skills%2Fpipa-triggers%2F@cdba18fc2c6cc460ad2a3270f9894dd8984ba3e13842a0119de76e84adcc44fd
Security Audit — socket — pipa-triggers