chatbot-review

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the composio command-line tool through the bash environment to discover and execute toolkit actions. These commands are part of the intended functionality for managing chatbot integrations and do not exhibit malicious behavior.
  • [PROMPT_INJECTION]: The skill includes an Indirect Prompt Injection surface as it processes external chatbot conversation logs which are considered untrusted data.
  • Ingestion points: External conversation logs are retrieved in Step 2 of the workflow.
  • Boundary markers: No explicit delimiters or instructions to ignore potential commands within the data are present.
  • Capability inventory: The skill utilizes shell execution and the composio CLI toolset.
  • Sanitization: There is no evidence of sanitization or filtering applied to the ingested conversation data before analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 08:13 PM
Security Audit — agent-trust-hub — chatbot-review