webex-incident-workflow

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues or malicious patterns were identified in the skill's logic or metadata.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection attack surface as it ingests untrusted data from incident alerts and WebEx webhook submissions (e.g., Adaptive Card actions). This is typical for incident management automation.
  • Ingestion points: External data enters through WebEx webhooks (attachmentActions) and incident symptoms from alerting systems.
  • Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within the processed data.
  • Capability inventory: The skill can create WebEx rooms, post messages, add memberships, create/update ServiceNow incidents via MCP scripts, and record logs in GAIT.
  • Sanitization: The provided instructions do not include specific sanitization or validation logic for the external data ingested.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 05:26 PM
Security Audit — agent-trust-hub — webex-incident-workflow