feedback-digest
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions and workflow are consistent with the stated purpose of analyzing customer feedback. No signs of obfuscation, persistence mechanisms, or unauthorized privilege escalation were identified.
- [COMMAND_EXECUTION]: The skill utilizes the Bash tool to interact with the Composio CLI (
composio search,composio execute,composio link). These operations are used as intended by the vendor (composio-community) to discover and fetch data from connected integrations. - [PROMPT_INJECTION]: Surface for Indirect Prompt Injection detected. The skill ingests untrusted data from external feedback platforms (Delighted, GatherUp, Gleap, Simplesat). While this data could contain adversarial instructions, the risk is mitigated by the skill's narrow focus on analysis and the
disable-model-invocationconfiguration which restricts autonomous model actions. No explicit boundary markers are present in the interpolation steps.
Audit Metadata