bug-report
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the composio CLI to execute tool actions for fetching ticket details from Gorgias and creating issues in Linear. These commands are necessary for the skill's workflow and occur within the user's authenticated environment.
- [PROMPT_INJECTION]: An indirect prompt injection surface is present because the skill processes untrusted ticket content from Gorgias to generate bug reports. Ingestion points: Ticket message data from GORGIAS_GET_TICKET. Boundary markers: Absent. Capability inventory: LINEAR_CREATE_LINEAR_ISSUE used to write data. Sanitization: Absent. While this is a vulnerability surface, it is inherent to the skill's primary purpose of processing ticket data.
Audit Metadata