connect
Pass
Audited by Gen Agent Trust Hub on Apr 25, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references official vendor packages from standard registries, including
composio,composio-langchain, and@composio/core. - [DATA_EXFILTRATION]: The skill facilitates data movement between third-party services as its core function. It correctly recommends using environment variables for API key management and relies on OAuth for secure service-to-service communication.
- [PROMPT_INJECTION]: The skill processes data from external integrations like Gmail and Slack, which presents a surface for indirect prompt injection. 1. Ingestion points: Data from integrated apps (SKILL.md). 2. Boundary markers: Not explicitly defined in the provided instructions. 3. Capability inventory: Execution of actions in external apps, including write operations (SKILL.md). 4. Sanitization: No specific sanitization logic is described in the skill text.
Audit Metadata