freshservice-automation
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface.
- Ingestion points: Untrusted ticket data ingested through
FRESHSERVICE_LIST_TICKETSandFRESHSERVICE_GET_TICKETas documented inSKILL.md. - Boundary markers: The instructions lack explicit delimitation or warnings to the agent to ignore instructions embedded within retrieved ticket descriptions.
- Capability inventory: The skill provides extensive write capabilities including
FRESHSERVICE_CREATE_TICKET,FRESHSERVICE_BULK_UPDATE_TICKETS, andFRESHSERVICE_CREATE_TICKET_OUTBOUND_EMAILwhich could be manipulated by malicious ticket content. - Sanitization: No evidence of input validation or content sanitization before processing ticket data.
- [EXTERNAL_DOWNLOADS]: External Infrastructure Dependency.
- The skill documentation in
SKILL.mddirects users to connect tohttps://rube.app/mcpfor tool functionality. This is a functional dependency for the Rube/Composio MCP integration. - [SAFE]: Self-referential Security Metadata.
- The
skill-report.jsonfile contains internal audit data (security_auditblock) that asserts a 'safe' risk level and 'safe_to_publish' status. These claims are evaluated as metadata and do not influence the independent security verdict.
Audit Metadata