connect
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documentation references official packages such as
composioand@composio/core. These resources are hosted on standard registries and belong to the skill's authoring organization. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon data from 1000+ external applications, which inherently introduces a surface for indirect instructions.
- Ingestion points: Data feeds from integrated applications (Gmail, Slack, GitHub, etc.) as described in
SKILL.md. - Boundary markers: Not specified in the skill body.
- Capability inventory: Ability to perform network-based actions and data modifications across integrated platforms as defined in the examples and supported apps section.
- Sanitization: Not documented within the skill's integration instructions.
Audit Metadata