composio
Fail
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill provides instructions to read API keys from sensitive local files, specifically
/data/workspace/composio-gateway/.envandworkspace/.env, and subsequently use these keys in network-connected SDKs and HTTP clients, which constitutes a credential exfiltration pattern. - [CREDENTIALS_UNSAFE]: The skill directs the agent to retrieve and handle plain-text credentials from environment configuration files rather than using secure platform-level secret management.
- [PROMPT_INJECTION]: The skill contains explicit 'CRITICAL' instructions to bypass the platform's security proxy (
sc-proxy) and override network proxy settings (HTTP_PROXY/HTTPS_PROXY) when communicating with the gateway. - [DYNAMIC_EXECUTION]: The skill provides templates and encourages the agent to generate and execute Python scripts at runtime for complex workflows, including browser automation via Playwright and multi-step media uploads to Twitter.
- [COMMAND_EXECUTION]: Extensive use of shell-based
curlcommands and Python subprocess execution to interact with internal and external API endpoints. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from multiple high-value external platforms and possesses the capability to perform actions based on that data, creating a vulnerability to indirect prompt injection.
- Ingestion points: Fetches data from Gmail, GitHub issues, Notion blocks, Google Docs, and arbitrary web page content via Playwright.
- Boundary markers: The instructions lack delimiters or explicit warnings to prevent the agent from following commands embedded within the retrieved external content.
- Capability inventory: Significant capabilities including sending emails, posting to social media, modifying repository content, and executing arbitrary code.
- Sanitization: No evidence of input validation, filtering, or sanitization before external content is processed or interpolated into agent prompts.
Recommendations
- AI detected serious security threats
Audit Metadata