composio

Fail

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: HIGHCREDENTIALS_UNSAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill provides instructions to read API keys from sensitive local files, specifically /data/workspace/composio-gateway/.env and workspace/.env, and subsequently use these keys in network-connected SDKs and HTTP clients, which constitutes a credential exfiltration pattern.
  • [CREDENTIALS_UNSAFE]: The skill directs the agent to retrieve and handle plain-text credentials from environment configuration files rather than using secure platform-level secret management.
  • [PROMPT_INJECTION]: The skill contains explicit 'CRITICAL' instructions to bypass the platform's security proxy (sc-proxy) and override network proxy settings (HTTP_PROXY/HTTPS_PROXY) when communicating with the gateway.
  • [DYNAMIC_EXECUTION]: The skill provides templates and encourages the agent to generate and execute Python scripts at runtime for complex workflows, including browser automation via Playwright and multi-step media uploads to Twitter.
  • [COMMAND_EXECUTION]: Extensive use of shell-based curl commands and Python subprocess execution to interact with internal and external API endpoints.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from multiple high-value external platforms and possesses the capability to perform actions based on that data, creating a vulnerability to indirect prompt injection.
  • Ingestion points: Fetches data from Gmail, GitHub issues, Notion blocks, Google Docs, and arbitrary web page content via Playwright.
  • Boundary markers: The instructions lack delimiters or explicit warnings to prevent the agent from following commands embedded within the retrieved external content.
  • Capability inventory: Significant capabilities including sending emails, posting to social media, modifying repository content, and executing arbitrary code.
  • Sanitization: No evidence of input validation, filtering, or sanitization before external content is processed or interpolated into agent prompts.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 17, 2026, 04:28 AM
Security Audit — agent-trust-hub — composio