customer-winback

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill utilizes platform-native tools and established integrations (Gorgias, HubSpot, Gmail) to perform legitimate business operations.
  • [SAFE]: The workflow includes a manual review checkpoint, requiring the user to select and approve email drafts before any automated actions are taken in Gmail.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from customer support tickets (Gorgias) to identify pain points. This creates a surface for indirect prompt injection where malicious ticket content could attempt to influence the agent's behavior. However, this is a known risk inherent to data processing tasks and is mitigated here by the requirement for human confirmation before tool execution.
  • [COMMAND_EXECUTION]: The skill uses the composio CLI to search for and execute tools. These are authorized platform operations within the context of the skill's purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 08:13 PM
Security Audit — agent-trust-hub — customer-winback