intercom-resolve

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the composio CLI to interact with Intercom services, including searching for tools, retrieving schemas, and managing conversations. These operations are performed using the vendor's native platform tools and are consistent with the skill's documented purpose.
  • [PROMPT_INJECTION]: The skill processes untrusted external data from Intercom conversations, which presents a surface for indirect prompt injection.
  • Ingestion points: User messages and conversation history are retrieved from Intercom via composio execute as described in SKILL.md.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands within conversation data are provided in the workflow.
  • Capability inventory: The skill has the ability to reply to or close conversations through the composio toolset.
  • Sanitization: There is no evidence of sanitization or content validation for the messages processed from the external service.
  • Mitigation: The skill includes a manual human-in-the-loop checkpoint by requiring the agent to 'Ask the user before sending any replies or changing conversation status', significantly reducing the risk of autonomous exploitation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 08:14 PM
Security Audit — agent-trust-hub — intercom-resolve