connect-recommend
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFE
Full Analysis
- Indirect Prompt Injection Surface: The skill utilizes tools to fetch and analyze content from external websites (via user-provided URLs). While this is a functional requirement for automated business research, it creates a potential surface for indirect prompt injection if a website contains hidden instructions intended to influence the agent. This is mitigated by the skill's design, which requires the user to manually verify and confirm all gathered research findings before they are used to generate recommendations.
- Project Context Awareness: The skill performs read-only operations on the local codebase, such as scanning for configuration files and searching for Stripe-specific code patterns (e.g., API keys, charge patterns). These operations are used to supplement the business research and are limited to the scope of the integration recommendation.
- Automated Research Patterns: The skill uses web search and fetch tools to identify business models, fee structures, and onboarding preferences. It operates under a clear trust model where high-confidence inferences are suggested for confirmation and low-confidence items are presented as open questions, ensuring the user remains the final authority on the configuration.
Audit Metadata