Pipeworx cfpb

PassAudited by ClawScan on May 10, 2026.

Overview

This is a read-only CFPB complaint lookup skill that uses a third-party Pipeworx MCP gateway, with no local code, install steps, credentials, or persistence shown.

This skill appears proportionate for searching public CFPB complaint data. Before installing, understand that it depends on a third-party Pipeworx MCP endpoint and that your query text may be sent there; no local code, credentials, or persistence are shown in the provided artifacts.

Findings (2)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

Your CFPB search terms and requests may be sent to the Pipeworx MCP gateway.

Why it was flagged

The skill routes its MCP tool use through a third-party hosted gateway. This is aligned with the stated CFPB lookup purpose, but it means user queries and returned data pass through that external service boundary.

Skill content
"url": "https://gateway.pipeworx.io/cfpb/mcp"
Recommendation

Use it for non-sensitive CFPB research queries, and review Pipeworx's trust/privacy posture if your searches are confidential.

What this means

You are trusting the hosted MCP endpoint rather than locally reviewed code.

Why it was flagged

The artifacts do not include source code or a project homepage for the hosted MCP service. This is not suspicious by itself, but it limits independent review of the remote server implementation.

Skill content
Source: unknown; Homepage: none; No code files present — this is an instruction-only skill.
Recommendation

Prefer this skill when you are comfortable relying on the Pipeworx-hosted service; avoid sending sensitive search context unless you trust that provider.