merge-tickets

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill utilizes 'composio' CLI commands to interact with the Gorgias API. These commands are specific to the skill's purpose of listing and retrieving ticket details and do not involve unauthorized file access or network exfiltration.
  • [PROMPT_INJECTION]: The skill processes ticket subjects and messages which are untrusted external inputs, creating a surface for indirect prompt injection. 1. Ingestion points: GORGIAS_LIST_TICKETS and GORGIAS_GET_TICKET in SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: composio CLI. 4. Sanitization: Absent. The risk is assessed as safe as the output is a comparative report for human review rather than an automated action.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 08:14 PM
Security Audit — agent-trust-hub — merge-tickets