connect

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation references official packages such as composio and @composio/core. These resources are hosted on standard registries and belong to the skill's authoring organization.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon data from 1000+ external applications, which inherently introduces a surface for indirect instructions.
  • Ingestion points: Data feeds from integrated applications (Gmail, Slack, GitHub, etc.) as described in SKILL.md.
  • Boundary markers: Not specified in the skill body.
  • Capability inventory: Ability to perform network-based actions and data modifications across integrated platforms as defined in the examples and supported apps section.
  • Sanitization: Not documented within the skill's integration instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:29 AM
Security Audit — agent-trust-hub — connect