nps-collect
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
composioCLI tool via Bash to search for toolkits and execute data retrieval/sending operations. This is consistent with the skill's stated purpose and use of the author's own platform tools. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources including customer surveys and CRM records (Gorgias, HubSpot, Satismeter, Delighted). This represents an attack surface where malicious content in feedback could attempt to influence the agent's output, though this is a standard risk for feedback analysis tasks.
- Ingestion points: External data fetched via
composio executefrom third-party toolkits inSKILL.md. - Boundary markers: Absent.
- Capability inventory: Shell command execution via
composio execute. - Sanitization: None specified in the instructions.
Audit Metadata