composio

Pass

Audited by Gen Agent Trust Hub on Mar 27, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing official Composio SDK packages from standard package registries (PyPI and NPM). These are recognized tools for the integration platform described.\n- [PROMPT_INJECTION]: The skill documents features for ingesting and processing data from external, untrusted sources such as GitHub, Slack, and Gmail, which presents an indirect prompt injection surface.\n
  • Ingestion points: Reads content from third-party applications via sessions and triggers as described in sdk-reference.md and auth-and-triggers.md.\n
  • Boundary markers: No specific delimiters or instructions for isolating untrusted tool outputs are included in the reference snippets.\n
  • Capability inventory: The skill provides a large suite of capabilities across multiple connected accounts, including file writes, messaging, and repository management (sdk-reference.md).\n
  • Sanitization: The patterns provided do not include explicit sanitization or validation logic for the external data being processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 27, 2026, 12:41 AM
Security Audit — agent-trust-hub — composio