nps-collect

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the composio CLI tool via Bash to search for toolkits and execute data retrieval/sending operations. This is consistent with the skill's stated purpose and use of the author's own platform tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources including customer surveys and CRM records (Gorgias, HubSpot, Satismeter, Delighted). This represents an attack surface where malicious content in feedback could attempt to influence the agent's output, though this is a standard risk for feedback analysis tasks.
  • Ingestion points: External data fetched via composio execute from third-party toolkits in SKILL.md.
  • Boundary markers: Absent.
  • Capability inventory: Shell command execution via composio execute.
  • Sanitization: None specified in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 08:13 PM
Security Audit — agent-trust-hub — nps-collect