zscaler-zia
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it integrates untrusted data from the Zscaler environment with high-privilege capabilities.
- Ingestion points: The skill fetches external data using tools such as
list_firewall_rules,list_url_filtering_rules,list_dlp_dictionaries, andlist_vpn_credentials. - Boundary markers: There are no boundary markers or instructions defined to prevent the agent from interpreting content within the API responses as commands.
- Capability inventory: The skill includes high-impact tools like
create_firewall_rule,update_firewall_rule, anddelete_firewall_rulewhich can modify the network's security configuration. - Sanitization: No evidence of data sanitization or validation is present in the skill instructions.
Audit Metadata