customer-winback
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill utilizes platform-native tools and established integrations (Gorgias, HubSpot, Gmail) to perform legitimate business operations.
- [SAFE]: The workflow includes a manual review checkpoint, requiring the user to select and approve email drafts before any automated actions are taken in Gmail.
- [PROMPT_INJECTION]: The skill ingests untrusted data from customer support tickets (Gorgias) to identify pain points. This creates a surface for indirect prompt injection where malicious ticket content could attempt to influence the agent's behavior. However, this is a known risk inherent to data processing tasks and is mitigated here by the requirement for human confirmation before tool execution.
- [COMMAND_EXECUTION]: The skill uses the
composioCLI to search for and execute tools. These are authorized platform operations within the context of the skill's purpose.
Audit Metadata