managing-freshservice
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill implements a core helper function
fs_apithat executes shell commands viacurlto interact with the Freshservice API. It also utilizesjqandcolumnfor parsing and formatting the returned data. - [DATA_EXFILTRATION]: The skill performs network operations to
freshservice.comusing thecurlutility. Authentication is correctly managed through environment variables (FRESHSERVICE_API_KEY), ensuring secrets are not hardcoded or exposed in logs. - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests and processes data from an external platform (Freshservice tickets, assets, and CMDB items) which may contain user-controllable text.
- Ingestion points: API GET requests in
SKILL.mdfor tickets, assets, changes, and CMDB items. - Boundary markers: None implemented for processed text.
- Capability inventory: Network access via
curl, local processing viajqandcolumn(SKILL.md). - Sanitization: None; data is piped directly into processing utilities.
Audit Metadata