zscaler-zia

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it integrates untrusted data from the Zscaler environment with high-privilege capabilities.
  • Ingestion points: The skill fetches external data using tools such as list_firewall_rules, list_url_filtering_rules, list_dlp_dictionaries, and list_vpn_credentials.
  • Boundary markers: There are no boundary markers or instructions defined to prevent the agent from interpreting content within the API responses as commands.
  • Capability inventory: The skill includes high-impact tools like create_firewall_rule, update_firewall_rule, and delete_firewall_rule which can modify the network's security configuration.
  • Sanitization: No evidence of data sanitization or validation is present in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 04:29 PM
Security Audit — agent-trust-hub — zscaler-zia